Effective / last updated 20 August 2026

Subprocessors and service providers

These are the providers actually used by the Inficy production deployment. Providers we have not deployed are not listed.

Current providers

  • Supabase: Managed Postgres database, authentication and object storage. Data category: Account identifiers, workspace records, execution metadata, sealed evidence artifacts. Processing location: European Union.
  • Cloudflare: Application hosting, edge delivery and network protection. Data category: HTTP request metadata (IP address, user agent) in transit. Processing location: Global edge network.
  • NexArt: Optional certification of a specific execution, on explicit request. Data category: The Project Bundle hash and the artifact you choose to certify. Processing location: European Union.

NexArt Node is an optional path

Normal recording stays inside the Inficy capture and storage path. Nothing is submitted to the NexArt Node unless you explicitly request certification of a specific execution; in that case the canonical Project Bundle for that execution is submitted for certification. Private disclosure (opening) material for confidential executions is not submitted.

Payments

No card payment processor is enabled today; there is no self-serve checkout during the pilot. When card payments are enabled, the payment processor will handle card details directly and will be added to this page before it goes live. Inficy does not store card numbers.

Email, analytics and error monitoring

Transactional authentication email is sent through the managed authentication provider listed above. No third-party product-analytics, advertising or session-recording provider is deployed. Product milestones are recorded in our own database only.

International transfers

Database, authentication and object storage are hosted in the European Union. Application hosting and network protection run on a global edge network, so request metadata (such as IP address and user agent) may be processed outside the UK and EEA in transit. The exact transfer safeguards in each provider contract require confirmation before we describe them specifically; we do not assert adequacy decisions or specific contractual mechanisms we have not verified.

Changes and data processing agreements

We will update this page when a provider is added or removed. A formal data processing agreement is not yet published; customers who require one contractually should contact contact@artnames.io before onboarding.