Sub-processors

Everyone who processes data on Maskbreak's behalf, what they do, and where they sit. New sub-processors that process customer data are announced at least 30 days in advance, with right to object — the change log below is the public record.

Last updated 19 July 2026 · maintained by Sentinel Edge Networks LTD

Current sub-processors

ProviderPurposeData touched
CloudflareCDN, TLS termination, edge caching, first-pass scanner verdict at the edgeRequest metadata (IP, headers) in transit
RailwayApplication hostingAll application traffic and data in transit
TursoPrimary database (managed libSQL), encrypted at restAccount data, hashed lookup records
ResendTransactional email (verification, notices)Email address, message content
UpstashDurable rate-limit state (Redis) for authentication and abuse-sensitive endpointsClient IP addresses as short-TTL rate-limit keys — no account data
Amazon Web Services (S3)Encrypted nightly database backups for disaster recovery — EU Stockholm region (eu-north-1)Full encrypted database snapshots, 60-day rolling retention
GoogleSign-In only (OAuth) — no analytics, no advertisingOAuth identity assertion
GitHubSign-In only (OAuth) — no analytics, no advertisingOAuth identity assertion
Have I Been PwnedPassword breach check via k-anonymity5-character SHA-1 prefix only — never the password
Network & device intelligence providersVPN/proxy classification and device-integrity signals for evaluationsRequest network metadata; named to customers under DPA
Fonts are self-hosted. There are no advertising or analytics providers on this list because there are none — see the Privacy Policy and Cookie Policy for the full data-handling picture.

Change log

DateChange
2026-08-02Added and removed Dreamdata (business-to-business marketing attribution) on the same day. It was live on public marketing pages for approximately 30 minutes. During that window its account-level component sent page URL, page title, canonical URL, referring URL and the requesting IP address to Dreamdata, which uses them to estimate the organisation a visit came from. Its visitor-level component was gated behind analytics consent, which this site does not grant — with one exception we want to be explicit about: the gate is read from Google’s consent framework, so a visitor whose browser blocked Google Tag Manager would have had the visitor-level component, including form tracking, initialise normally. It never ran on the console or on any signed-in page, and it received no customer API or evaluation data at any point. It has been fully removed; no Dreamdata code, endpoint or Content-Security-Policy entry remains. Recorded here for completeness rather than because any obligation attaches to a provider that is no longer used.
2026-07-19Added GitHub (Sign-In only, OAuth) — an optional “Sign in with GitHub” for Maskbreak accounts. It touches only the account holder’s own OAuth identity assertion, never customer end-user evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §3 were updated in the same change.
2026-07-18Added Upstash (rate-limit state) and Amazon Web Services / S3 (encrypted nightly backups). Both were already live infrastructure — this is a completeness correction to the published list, not a new-processor onboarding, so the 30-day advance-notice clause does not apply. Privacy Policy §5 and the security whitepaper were updated in the same change.
2026-07-16Page published. List matches the sub-processors already disclosed in the Privacy Policy — no additions or removals.

Getting notified

Enterprise customers under a signed DPA receive direct notification of sub-processor changes. Everyone else can watch this page or the changelog — any change lands in both at least 30 days before a new data-processing sub-processor goes live.

Questions or objections: [email protected].