Template. This document is a starting point and has not been reviewed by counsel. Have a qualified lawyer review it before launch.

Subprocessors

Last updated July 3, 2026

silobase is an upload-only static analyzer. You upload a Salesforce metadata export and it maps every email-sending path — Flows, workflow rules, email alerts, Apex senders, approval emails, org-wide sender and deliverability settings — into a blast-radius manifest, a safe-test plan, a deliverability checklist, and an exportable evidence ledger. To run that service we rely on a short list of third-party vendors (“subprocessors”) that store, process, or transmit data on our behalf. This page lists every one of them.

{{TODO: confirm legal operating entity — likely Peakure LLC}} is the controller of the data described below. The vendors in the table act as processors on our instructions. This list is the complete set of subprocessors for the current version of the service.

What silobase does and does not read

silobase reads metadata only. It parses the structure of your export to find where email would send. It never reads email content, CRM records, or contact data. It never writes back to your org. It never sends email from your Salesforce org — it maps the paths that would send, it never triggers one. Recipient resolution is heuristic, because v1 is upload-only with no live-org connection. silobase is an independent tool: it is not a Salesforce product, not endorsed by Salesforce, and not Mailtrap.

Current subprocessors

SubprocessorPurposeData processed
SupabasePostgres database, authentication, and file storage for uploaded metadata (storage bucket metadata-uploads).The Salesforce metadata exports you upload, your account details (name, email), and the org / sandbox identifiers you enter.
StripePayment and subscription processing for the $99 Report and the $39/mo Release Ledger.Billing details, handled directly by Stripe. Card numbers are entered with Stripe and are not stored by silobase.
VercelApplication hosting and Vercel Analytics, which is cookieless.Usage and server log data (such as request metadata). Analytics is cookieless.
ResendTransactional email delivery — account, receipt, and notification emails sent by silobase to you.Your email address.
Anthropic (Claude API)Generates plain-language explanations of detected risk and drafts the safe-test plan from the deterministic detector’s output.Detector findings only — not your raw org data or uploaded metadata. The deterministic detector owns risk classification; the Claude API only explains it.

Hosting and processing regions

{{TODO: confirm hosting and data-processing regions for Supabase, Stripe, Vercel, Resend, and Anthropic}}

What subprocessors do not receive

No subprocessor receives email content, CRM records, or contact data — silobase does not have that data, because it reads metadata only. No subprocessor writes back to your Salesforce org. The Claude API receives detector findings, not your raw metadata export.

Security posture

The service is hosted on Vercel with data stored in Supabase (encryption at rest as provided by Supabase). Authentication is handled by Supabase, with optional two-factor / authenticator (2FA) available. Data tables use row-level security. Uploaded metadata can be deleted. Analytics is cookieless.

How we notify you of changes

We may add, remove, or replace a subprocessor as the service changes. When we do, we update this page and its Last updated date. Continued use of silobase after a change means the updated list applies to your account.

Contact

Questions about this list or about how your data is processed go to privacy@silobase.io. For support and refunds, email support@silobase.io. For security or vulnerability reports, email security@silobase.io. See also our Privacy Policy.

Questions about this policy? See Contact or read the Privacy Policy.
    Subprocessors — silobase