Retour au Trust Center
En vigueur depuis: 2026-09-28
Disponible uniquement en anglais. Ce document juridique est fourni en anglais en tant que version faisant foi. L'interface du Trust Center est traduite dans votre langue.

Sub-processors, Aevral

Effective Date: 2026-09-28.

This list discloses the sub-processors Better ISMS (ISMS Copilot) engages to provide Aevral, the code security product at app.aevral.com: repository scanning and pull request security review through the Aevral GitHub App. For the code, pull requests and findings Aevral processes, your organization is the controller and Better ISMS is the processor (DPA §1.7). For your Aevral account and billing data, Better ISMS is the controller (privacy policy).

Scope. This list covers Aevral only. The ISMS Copilot chat sub-processors are on the trust center home page. Every provider below is already a sub-processor of ISMS Copilot for other products.

How Aevral processes your code

  • What is read. A scan reads the repository archive at one commit, when you press Scan, on a schedule you set, or through your Aevral API key. A pull request review reads the diff and up to 40 changed files at head. Only repositories where you installed the App are read.
  • What goes to the AI model. File paths and redacted file contents (scan), or the pull request title, body, diff and changed files (review), after known credential patterns and secret files are removed. Secrets in unusual formats may not be caught, so keep secrets out of your repositories.
  • What is stored. Raw code is processed in memory and not stored. Findings, with short code excerpts and suggested fixes, and review results are stored in the EU, while the App is installed and for 12 months after you uninstall it (findings not seen again for 24 months are deleted earlier). On request to privacy@ismscopilot.com we return or delete them within 30 days.
  • What is written back. Advisory checks and inline review comments on GitHub. Aevral never commits, pushes or merges.
  • No training. No provider below trains on your code.

AI model sub-processors

Sub-processor (legal entity)PurposeRegion / transferRetention
OpenRouter, Inc. (US)Routes each AI request to the closed host set below; the first US recipient of your codeUnited States. OpenRouter's SCCs (Module Two) plus supplementary measuresZero data retention and no data collection required on every request (zdr: true, data_collection: "deny")
↳ Together AI, Inc. (US)Runs the GLM-5.3 open-weights modelUnited States. Onward SCCsZero retention
↳ Fireworks AI, Inc. (US)Runs the GLM-5.3 open-weights modelUnited States. Onward SCCsZero retention
↳ Inceptron AB (Sweden)In the pinned set; does not currently serve GLM-5.3EU (Sweden). Onward transfer from OpenRouter to an EU recipientZero retention

The host set is pinned in code and is never widened without a new notice. OpenRouter does not pin the region of each request, so a request may be served in the US or the EU. GLM-5.3 is an open-weights model of Chinese authorship; its author does not receive your code, and no Chinese-jurisdiction host is in the pinned set.

Infrastructure and service sub-processors

Sub-processor (legal entity)PurposeData processedRegion / transfer
Fly.io, Inc. (US)Runs the Aevral workerCode in memory during a scan or review; not storedEU (Paris). US-incorporated entity under SCCs
Supabase, Inc. (US)Database and sign-inAccounts, organizations, findings, review resultsEU (Frankfurt). US-incorporated entity under SCCs. Underlying infrastructure: AWS
Functional Software, Inc. dba Sentry (US)Error monitoring for the worker and consoleError events; recognized credential patterns are redacted, but free-form error text can contain code-derived contentEU ingest (Germany). US entity under SCCs
Vercel Inc. (US)Hosts the Aevral console, site and docsRequest metadata at the edgeGlobal edge network. SCCs
Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.)BillingBilling data; no codeEU (Ireland) / US. SCCs

Not sub-processors

  • GitHub, Inc. hosts your repositories and receives Aevral's checks and comments under your own agreement with GitHub. Aevral reads and writes through installation-scoped tokens on your instruction. GitHub is not a sub-processor of Better ISMS. The same applies to the heyGRC GitHub App.
  • Tally BV (Belgium) hosts Aevral's issue and contact forms. It receives only what you submit in a form and, for issue reports, the prefilled pull request URL. Aevral sends it no repository content, and it processes that form data for Better ISMS as controller, not as a sub-processor of your data.
  • Cursor, Claude Code, Codex. When you choose to open a finding in your own coding agent, you send it there yourself.

Change notification

Changes to this list follow DPA §2.4: materially adverse changes are announced at least 30 days ahead; control-neutral changes are published here and in the change log. Questions or objections: privacy@ismscopilot.com.


This Aevral Sub-processor List is published by Better ISMS (ISMS Copilot).