Ring 0 is open to design partners running agents against production systems. Request access

Legal

Who else touches it, and where.

The complete list, versioned. We give 30 days' notice before adding one, and you may object on data protection grounds.

01 / current list

SubprocessorPurposeDataRegions
Amazon Web ServicesBare-metal hosts for the managed sandbox fleet and object storageWorkload data in the managed service onlyUS, EU, IN, JP, SG, BR
Google Cloud PlatformManaged fleet capacity in selected regionsWorkload data in the managed service onlyUS, EU
CloudflareDNS, WAF, and TLS termination for the control planeRequest metadata and IP addressesGlobal edge
NeonManaged Postgres for control-plane stateSession metadata, policy versions, chain headsEU
StripePayment processing and invoicingBilling contact and payment detailsUS, EU
WorkOSSSO and SCIM directory syncAccount identity and group membershipUS
SlackApproval routing where a customer enables itApproval requests including argument summariesUS
ResendTransactional email including approval requestsWork email address and message contentUS, EU
PlausibleWebsite analytics, cookieless and aggregatedPage views and referrers, no personal identifiersEU
LinearSupport ticket trackingSupport conversations you send usUS

02 / by deployment

How much of this list applies to you.

managed

All of them

We run the fleet, so the hosting and storage providers process workload data.

byoc

Control plane only

Workload data stays in your account. Only Neon, Cloudflare, and the notification providers are involved.

air-gapped

None

Nothing leaves your network. There is no phone-home and no telemetry.

03 / notifications

To be told when this list changes, email legal@velone.in and we will add you to the notice list. Changes are announced 30 days before they take effect, and previous versions of this page stay available on request.

Ring 0

Need this in a questionnaire format?

We keep a pre-filled CAIQ and SIG Lite ready. Ask and we will send them the same day.

curl -fsSL velone.in/install.sh | sh