Sub-Processor Disclosure
The third-party vendors that process customer personal data on TrueStake's behalf, with honest notes on data-processing agreement status and which vendors handle only public on-chain data.
What a sub-processor is
A sub-processor is a third-party vendor that processes personal data on TrueStake's behalf. The distinction matters: some vendors in our stack receive only public Ethereum on-chain data (no connection to your identity), while others touch data that links to you as a person.
PII sub-processors — vendors that touch personal data
These vendors receive or process personal data about TrueStake customers (data that can be linked to an identifiable person):
| Vendor | Role | Notes |
|---|---|---|
| Supabase | Database, authentication, storage | Holds your email address, encrypted on-chain identifiers, and reward data. |
| Vercel | Web hosting, edge network, serverless functions | Processes session data and API requests. |
| Sentry | Error monitoring | Receives error reports. A PII scrubber strips address-pattern data before upload. |
| Cloudflare | DNS, WAF, Cloudflare Tunnel (node access) | Processes network requests including IP addresses in access logs. |
| Resend | Transactional email (auth magic links, incident notification) | Used to deliver authentication emails (magic links) and, if needed, incident notifications. Receives email addresses. |
| GitHub | Source code hosting, CI/CD | Holds developer credentials and source code. No customer personal data is in the source repository. |
| Stripe | Billing and payment processing | Holds billing address and payment card data — TrueStake stores only a Stripe customer ID, not the underlying payment data. |
| OVHcloud | Bare-metal hosting for the self-operated Ethereum node | Hosts our Ethereum node hardware (ADR-0041). Holds no customer account data and has no logical access to TrueStake systems, but has physical access to the machine that processes validator identifiers. |
Doppler (Secrets management) is listed for completeness — Holds service credentials only — no customer PII;
The following data sources receive queries about public Ethereum blockchain data only — no personal data, no email address, no identity linkage. They are data sources, not PII sub-processors:
| Vendor | What they receive |
|---|---|
| CoinGecko | Price oracle queries (public ETH/USD market data) |
| Kraken | Price oracle queries (public ETH/USD market data) |
| Coinbase | Price oracle queries (public ETH/USD market data) |
| beaconcha.in | Validator index lookups (public Ethereum network data) |
| Lighthouse (self-hosted) | Validator indices for beacon-chain queries; own-operated node, no third-party data sharing |
| Reth (self-hosted) | Block number and log queries; own-operated node, no third-party data sharing |
The infrastructure vendors listed above hold industry certifications:
- Supabase — SOC 2 Type II
- Vercel — SOC 2 Type II
- Sentry — SOC 2 Type II
- Cloudflare — SOC 2 Type II
- Stripe — PCI DSS Level 1
Honest deferral — formal DPAs
Standard data-processing agreements are available from every vendor in the table above. None has been formally executed. All 8 remain outstanding. That is the current state, and we would rather you read it here than discover it in diligence.
The condition we hold ourselves to is specific: no account is created for anyone outside the founder's own until an executed DPA is on file with every personal-data sub-processor then in active production use. It is recorded as requirement R5.4 in our internal security review packet, and the table above is the checklist it runs against — a vendor added to that table is a vendor added to the gate.
Two things this deliberately does not say. It does not describe a DPA's contents — only whether one is executed. And it does not reach vendors that hold no personal data — secrets management, price oracles, the node software itself — which sit outside the gate by design and are listed separately in our security review packet.
Vendor certifications (held by the vendor, not by TrueStake)
TrueStake itself holds no SOC 2, ISO 27001, or PCI certification. Their certifications do not transfer to TrueStake's application layer — they cover the vendor's own infrastructure and operations.
This list reflects TrueStake's sub-processor roster as of 2026-09-05. It will be updated when vendors are added or removed.
Citations
- [1]Security Posture — TrueStake vulnerability disclosure· Public security policy