Third Party Index

Snapshot 25253

Document
Subprocessor list
URL
https://www.rwx.com/docs/security/subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
157649 bytes
SHA-256 (raw)
feb9f0dd3c4670b26d726566f4a944d45c46a2c2143ab223566f7103d1025c17
SHA-256 (normalized text)
85906462d80f59b6bd25adbe2e60c1d66978b3d92404f647b45e2e7238760d02

Normalized text

Scripts and page chrome removed; this is what change detection compares.

RWX Documentation
Subprocessor list
Last updated: 2026-08-31
RWX uses the following third-party subprocessors to support delivery of our services. A subprocessor is a third party engaged by RWX to process personal data on behalf of our customers in connection with the RWX services.
Infrastructure & data storage
Subprocessor	Purpose	Data Categories	Processing Location
Amazon Web Services
Cloud infrastructure hosting, artifact storage (S3), application logs
Customer content, build artifacts, logs, account metadata	United States
Networking & DNS
Subprocessor	Purpose	Data Categories	Processing Location
Cloudflare
DNS and network services (does not store application or artifact data)
IP addresses, network metadata	United States
Monitoring, logging & observability
Subprocessor	Purpose	Data Categories	Processing Location
ClickHouse	System log storage and analysis	System logs, service metadata, identifiers	United States
Datadog	Metrics, logging, performance monitoring	Logs, service metadata, identifiers	United States
Customer support & incident management
Subprocessor	Purpose	Data Categories	Processing Location
Slack Technologies	Customer support communications and operational notifications	Messages, identifiers, log excerpts	United States
Google (Gmail / Google Groups)	Email-based customer support communications	Email addresses, message content	United States
PagerDuty	Incident management and alerting (limited to incident metadata)	Incident metadata, service identifiers	United States
Email & communications
Subprocessor	Purpose	Data Categories	Processing Location
Postmark	Transactional email delivery	Email address, message metadata	United States
Billing & payments
Subprocessor	Purpose	Data Categories	Processing Location
Stripe	Payment processing and subscription management	Billing contact info, payment metadata	United States
Bill.com	Invoicing and accounts payable	Billing contact info, invoice data	United States
Authentication & security
Subprocessor	Purpose	Data Categories	Processing Location
GitHub	Authentication (OAuth)	User identifiers	United States
WorkOS	Enterprise SSO and identity management	User identifiers, authentication metadata	United States
hCaptcha	Bot detection and abuse prevention	IP address, challenge metadata	United States
MaxMind	Fraud prevention and signup abuse detection (minFraud service)	Email address, IP address, user-agent string at signup	United States
Internal applications
Subprocessor	Purpose	Data Categories	Processing Location
Render	Application hosting of internal operational tooling	Account metadata	United States
Neon	Managed database services	Account metadata	United States
Customer-configured identity integrations
RWX supports optional integrations with third-party infrastructure and compute providers via OpenID Connect (OIDC). These integrations are configured and controlled by the customer, and RWX does not engage these providers as subprocessors.
Developer integrations
RWX integrates with customer repositories via customer-installed applications or webhooks, such as GitHub, GitLab, Forgejo, and Cursor Origin. These integrations are initiated and authorized by the customer, and operate under the customer's applicable terms with those providers. RWX only receives the events that the customer grants access to through these integrations.
Use of AI-assisted development tools
RWX employees may, on a limited and case-by-case basis, use AI-assisted development tools (such as Cursor or Claude Code) to debug or analyze customer-provided data for support or operational purposes. Such access is subject to RWX's internal access controls, logging, and data handling policies, and is limited to the minimum data necessary to perform the relevant task.
For questions regarding this list, please contact [email protected].