Third Party Index

Snapshot 20979

Document
Subprocessor list
URL
https://semantiqwall.com/en/trust/09-supplier-management
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
12533 bytes
SHA-256 (raw)
e83b4747697f868669bd54638d2aa89ac51ec8f69329afc901d9987cca9267bd
SHA-256 (normalized text)
14683135b303b9a49725b295e19224f36f8675d65c5dcd8516df397b2ce5a79d

Normalized text

Scripts and page chrome removed; this is what change detection compares.

← Trust Center
Supplier and Subprocessor Management
Version
1.0
Owner
Founder
Approved by
Murilo Martins (Founder) · 09/28/2026
Next review
2027-09-28 (annual or on significant change)
Scope
Every third party that hosts, processes or can access SemantiqWall systems or data, and the software supply chain (open-source dependencies).
1. Supplier inventory
Supplier	Purpose	Data it can access	Location	Status
Hostinger	VPS hosting (compute, disk, network, datacenter)	All platform data, logs and backups	Brazil (Campinas, São Paulo); ISO/IEC 27001:2022 certified (public statement); certificate and security documentation reviewed 2026-09-28 under Hostinger's confidentiality terms - the certified scope covers the VPS service we use	Active - subprocessor
Backblaze	Off-site backup storage (B2, bucket with Object Lock)	Encrypted backup packages only; it holds no key to open them	United States (us-east)	Active - subprocessor
Resend	Transactional e-mail (watch-list confirmation and vendor alerts)	Recipient e-mail, name and message content	Region sa-east-1 (São Paulo)	Active - subprocessor
GoDaddy (Titan Mail)	Company mailbox [email protected]	Messages sent to us (support, privacy and security requests)	Mailbox server location not stated	Active - subprocessor
GitHub	Private source code repository; deploy key; SemantiqWall GitHub App for customers who install it	Our code; for App users, the files the customer allows and the pull requests we open	United States	Active - supplier; subprocessor only for GitHub App users
Anthropic	AI provider for optional case triage and remediation proposals	Case summary and evidence text, agent description, up to 4 files of the customer's code	United States	Optional - used only when configured
Meta (WhatsApp Cloud API)	Optional approval messages	Approver phone number, approval message	Meta infrastructure	Disabled
Certificate authorities (ACME, via Caddy)	TLS certificates	Domain names only	-	Active
GoDaddy (registrar)	semantiqwall.com registration and DNS (renews 2027-09-27)	DNS records	-	Active
Open-source packages (Composer, npm)	Application and SDK dependencies	None at runtime beyond the code itself	-	Pinned in lock files
The public list of subprocessors is kept in the privacy policy and updated before a new subprocessor starts receiving personal data. Customers can object by writing to [email protected].
2. Shared responsibility with suppliers
Area	Supplier is responsible for	SemantiqWall is responsible for
Hosting (Hostinger)	Datacenter physical and environmental security, hardware, hypervisor, network up to the VPS, media disposal	Everything inside the VPS: OS hardening and updates, firewall, SSH, application, database, backups, encryption, monitoring
E-mail (Resend, Titan)	Delivery infrastructure and security of their platforms	Account MFA, API key protection, content we send, domain authentication records
Code hosting (GitHub)	Platform security	Repository access, MFA, deploy keys, App permissions (least privilege: contents, pull requests, metadata)
AI provider	Model hosting and their data handling commitments	Sending only the minimum, treating output as untrusted, never letting AI decide allow/deny, turning the feature off if terms change
3. Selecting a new supplier
Before a supplier receives customer or personal data, the Founder checks and records in the security register:
purpose and the minimum data needed;
security evidence - SOC 2 or ISO 27001 report or a public security page;
data processing terms, including international transfer clauses when outside Brazil, breach notification and subprocessors;
data location and retention;
MFA available on the account;
how to leave: export and deletion.
A supplier handling customer data with no security evidence needs an exception (policy 00).
4. Requirements for suppliers
Suppliers must keep customer data confidential, use it only to provide their service to SemantiqWall, notify us of breaches affecting our data, and delete it at the end of the service. For today's suppliers these obligations come from their standard online terms, which are accepted rather than negotiated.
5. Review
Annually, and when a supplier changes its terms, location or ownership or has a breach: re-check section 3, confirm MFA on our account, and record the review.
First formal review of Hostinger - done 2026-09-28: datacenter location confirmed (Campinas, Brazil) in the Hostinger panel; ISO/IEC 27001:2022 certificate, physical security, media disposal and business continuity documentation reviewed in Hostinger's Trust Center (obtained under its confidentiality terms and kept privately; the certified scope covers VPS hosting and includes physical security and secure disposal of storage media); MFA confirmed on all supplier accounts (policy 01).
Commitment - rest of the first formal review: archive the data processing terms of Hostinger, Resend, GoDaddy, GitHub, Backblaze and Anthropic and review their security pages (owner: Founder, target 2026-10-31).
Supplier incidents follow policy 05.
6. Software supply chain
Dependencies are pinned (composer.lock, SDK lock files) and come only from official registries.
The GitHub App requests only the permissions it needs, and SemantiqWall never merges pull requests in customers' repositories.
Commitments: dependency alerts (target 2026-10-15), composer audit in CI and deploy (target 2026-11-30) and a Software Bill of Materials per release (target 2026-12-31), as set in policies 03 and 07.