Subprocessors

Last updated: August 11, 2026

Ruligent uses the following third-party subprocessors to deliver the service. We keep this list deliberately small.

Subprocessor Purpose Location Data categories
Vercel Application hosting (marketing site, dashboard, API) United States All service traffic in transit, including account data and agent activity data as it is served
Supabase Postgres database Region-configurable Account data (name, email, scrypt password hash, org name); agent tool-call metadata and bounded payload summaries; audit events; policies and settings
Stripe Payment processing and subscription billing United States Billing name and email, payment card details (held by Stripe only — Ruligent never stores card data), subscription status
Resend (optional) Transactional account-recovery email United States Recipient name and email address plus a short-lived password-reset link. Only active when password recovery is configured
Sentry (optional) Error reporting United States Error context: stack traces, request metadata; may incidentally include account identifiers. Only active when error reporting is enabled
PostHog (optional) Product analytics United States / EU Product usage events and account identifiers. Only active when analytics is enabled; see the Cookie Policy for opt-out

Changes to this list

We commit to updating this page before adding any new subprocessor. Customers with an executed Data Processing Addendum may object to a new subprocessor on reasonable data-protection grounds within the window specified in the DPA. To be notified of changes by email, ask us at www.ruligent.com/contact.

Note: webhooks are delivered to URLs your organization configures. Those receiving systems are your vendors, not our subprocessors.