Subprocessors
Third parties that process Evitrus customer data (Evidence Events, account data, or operational telemetry) for the managed cloud on evitrus.io.
Subprocessors
These providers may receive customer data in order to run the service.
| Subprocessor | Purpose | Data involved | Region |
|---|---|---|---|
| Hetzner Online GmbH | Compute, disk, and Kubernetes hosting for the API, data stores, and frontends | Evidence Events, account data, organisation audit logs, website/server logs | European Union (Germany) |
| Lettermint B.V. | Transactional email (password reset, usage and similar notices) | Account email addresses and the content of those messages | European Union (Netherlands) |
Business operations
These vendors support running Evitrus as a company. They do not host the customer evidence store. Some may see operator identity or Evitrus source in the course of internal work.
| Vendor | Role | Region |
|---|---|---|
| Linear | Issue tracking | United States |
| Slack | Internal team communication | United States |
| Cursor | AI-assisted software development | United States |
| Workspace identity for operator SSO (Cloudflare Access) | United States / EEA |
Other integrations (no customer data)
These services are used to operate Evitrus but do not receive Evidence Events, account contents, or other customer data.
| Integration | Role |
|---|---|
| Amazon Route 53 | DNS for *.evitrus.io. Name-resolution metadata only; application traffic is not proxied through AWS. |
| Cloudflare Zero Trust | Operator access to internal admin surfaces. Customer product traffic on app.evitrus.io / api.evitrus.io does not pass through this control. |
| GitHub | Source hosting, CI, and container registry for Evitrus software. Build artifacts and source, not the customer evidence store. |
| Mend Renovate | Automated dependency updates on Evitrus source repositories. Sees public/private source, not customer data. |
Notes
- Customer-installed exporters (Kubernetes, Terraform, EventBridge Lambda, GitHub Action) run in the customer environment and are not Evitrus subprocessors.
- Optional metric overlays (Datadog, Prometheus) are pulled on demand with customer credentials and are not stored as Evitrus’s system of record. Those vendors are the customer’s processors, not Evitrus subprocessors.
- Material changes to the subprocessor list are reflected on this page; customers are notified as required by the executable DPA.
- For the signed schedule attached to your DPA, write to legal@beneke-consulting.com.
Last updated: 2026-08-16.