Sub-processors, Aevral
Effective Date: 2026-09-28.
This list discloses the sub-processors Better ISMS (ISMS Copilot) engages to provide Aevral, the code security product at app.aevral.com: repository scanning and pull request security review through the Aevral GitHub App. For the code, pull requests and findings Aevral processes, your organization is the controller and Better ISMS is the processor (DPA §1.7). For your Aevral account and billing data, Better ISMS is the controller (privacy policy).
Scope. This list covers Aevral only. The ISMS Copilot chat sub-processors are on the trust center home page. Every provider below is already a sub-processor of ISMS Copilot for other products.
How Aevral processes your code
- What is read. A scan reads the repository archive at one commit, when you press Scan, on a schedule you set, or through your Aevral API key. A pull request review reads the diff and up to 40 changed files at head. Only repositories where you installed the App are read.
- What goes to the AI model. File paths and redacted file contents (scan), or the pull request title, body, diff and changed files (review), after known credential patterns and secret files are removed. Secrets in unusual formats may not be caught, so keep secrets out of your repositories.
- What is stored. Raw code is processed in memory and not stored. Findings, with short code excerpts and suggested fixes, and review results are stored in the EU, while the App is installed and for 12 months after you uninstall it (findings not seen again for 24 months are deleted earlier). On request to privacy@ismscopilot.com we return or delete them within 30 days.
- What is written back. Advisory checks and inline review comments on GitHub. Aevral never commits, pushes or merges.
- No training. No provider below trains on your code.
AI model sub-processors
| Sub-processor (legal entity) | Purpose | Region / transfer | Retention |
|---|---|---|---|
| OpenRouter, Inc. (US) | Routes each AI request to the closed host set below; the first US recipient of your code | United States. OpenRouter's SCCs (Module Two) plus supplementary measures | Zero data retention and no data collection required on every request (zdr: true, data_collection: "deny") |
| ↳ Together AI, Inc. (US) | Runs the GLM-5.3 open-weights model | United States. Onward SCCs | Zero retention |
| ↳ Fireworks AI, Inc. (US) | Runs the GLM-5.3 open-weights model | United States. Onward SCCs | Zero retention |
| ↳ Inceptron AB (Sweden) | In the pinned set; does not currently serve GLM-5.3 | EU (Sweden). Onward transfer from OpenRouter to an EU recipient | Zero retention |
The host set is pinned in code and is never widened without a new notice. OpenRouter does not pin the region of each request, so a request may be served in the US or the EU. GLM-5.3 is an open-weights model of Chinese authorship; its author does not receive your code, and no Chinese-jurisdiction host is in the pinned set.
Infrastructure and service sub-processors
| Sub-processor (legal entity) | Purpose | Data processed | Region / transfer |
|---|---|---|---|
| Fly.io, Inc. (US) | Runs the Aevral worker | Code in memory during a scan or review; not stored | EU (Paris). US-incorporated entity under SCCs |
| Supabase, Inc. (US) | Database and sign-in | Accounts, organizations, findings, review results | EU (Frankfurt). US-incorporated entity under SCCs. Underlying infrastructure: AWS |
| Functional Software, Inc. dba Sentry (US) | Error monitoring for the worker and console | Error events; recognized credential patterns are redacted, but free-form error text can contain code-derived content | EU ingest (Germany). US entity under SCCs |
| Vercel Inc. (US) | Hosts the Aevral console, site and docs | Request metadata at the edge | Global edge network. SCCs |
| Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.) | Billing | Billing data; no code | EU (Ireland) / US. SCCs |
Not sub-processors
- GitHub, Inc. hosts your repositories and receives Aevral's checks and comments under your own agreement with GitHub. Aevral reads and writes through installation-scoped tokens on your instruction. GitHub is not a sub-processor of Better ISMS. The same applies to the heyGRC GitHub App.
- Tally BV (Belgium) hosts Aevral's issue and contact forms. It receives only what you submit in a form and, for issue reports, the prefilled pull request URL. Aevral sends it no repository content, and it processes that form data for Better ISMS as controller, not as a sub-processor of your data.
- Cursor, Claude Code, Codex. When you choose to open a finding in your own coding agent, you send it there yourself.
Change notification
Changes to this list follow DPA §2.4: materially adverse changes are announced at least 30 days ahead; control-neutral changes are published here and in the change log. Questions or objections: privacy@ismscopilot.com.
This Aevral Sub-processor List is published by Better ISMS (ISMS Copilot).