> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lanesync.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Subprocessors

> Third-party services LaneSync uses to process customer data.

LaneSync uses the following subprocessors to deliver the hosted SaaS product. Enterprise customers may request notification of subprocessor changes via their DPA.

| Subprocessor                 | Purpose                                                                     | Data processed                                               | Location                               |
| ---------------------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------ | -------------------------------------- |
| Amazon Web Services (AWS)    | Cloud infrastructure — RDS, S3, KMS, CloudFront, EC2/ECS                    | Encrypted tenant metadata, evidence blobs, audit logs        | Configurable (default: ap-southeast-1) |
| GitHub (Microsoft)           | Source of truth for repos, issues, PRs, workflow runs; OAuth authentication | Repository metadata, issue/PR state (not stored source code) | United States                          |
| Sentry (Functional Software) | Error monitoring and performance tracing                                    | Stack traces, request metadata (PII minimized)               | United States                          |

## Customer-controlled subprocessors

LaneSync does not require customers to use specific CI or deployment providers. Customer CI pipelines (GitHub Actions by default) upload evidence to LaneSync — the customer controls which tools run in their pipelines (Trivy, Semgrep, etc.).

## Updates

Material changes to this list will be communicated to enterprise customers with 30 days notice.

Contact: **[security@lanesync.dev](mailto:security@lanesync.dev)**
