Subprocessors
Everyone who processes customer data on our behalf. If you are approving Libyears for a client, this is the list their administrator will ask for, and it is generated from the same file the application reads rather than maintained separately.
We notify customers before a new subprocessor begins handling their data. Everything below is in the United States; see security for what that means for transfers out of the EU and UK.
Processes your data
Handles payment, not your repositories
As merchant of record, they collect billing details directly. Card numbers never reach this application, which is why there is no payment form anywhere in it.
What is not on this list
No analytics provider, no session recording, no advertising network, and no AI vendor. The product sends nothing to a model, and the dashboard loads no third-party script.
The public data sources we read — the npm registry, OSV, and the rest — are not subprocessors, because none of them receives customer data. They are asked about public package names, and a private package name is never among them. They are listed on the attribution page.