Control over AI
Documentation
Compliance & vendors

Services and vendors

The services BeeSensible uses for detection, hosting, login, billing, and email, and what each service gets to see.

Sensitive-data detection runs on BeeSensible's own models, not on a third-party AI service. The services below support hosting, login, billing, email, and support.

In the detection itself:

ServiceUseLocation
ScalewayHosting of the API, dashboard, database, object storage, the login environment (Keycloak), and the service that anonymises PDFsEU (Netherlands; object storage and registry also France and Poland)
HetznerCompute for cloud detection and for sorting prompts into use-case categoriesEU (Germany)

In on-device mode, cloud detection is not used: the desktop app does the detection and the prompt sorting on the machine itself, and typed text never leaves the device.

Around the service:

ServiceUseLocation
Google / MicrosoftIdentity providers at sign-in (SSO), only at the moment of signing inUS
PaddleBilling, subscriptions, and seats (Merchant of Record)UK (adequacy decision)
BrevoInvitations, welcome emails, and reminders; a contact list of free users (email address and first name) for product emails, cleared as soon as the organisation pays or the account is deletedEU (France)
SlackMessages from the contact form, internal notices about how the service is running (counts only), and a notice when a new organisation is created (name, email domain, seats, plan)US
CloudflareCDN, security, and cookieless analytics for the website; not involved in the productUS
ProtonOur own mailbox for customer correspondence; not involved in the productSwitzerland (adequacy decision)
GitHubSource code, build pipeline, and hosting of our software images; no user dataUS

Keycloak, which users sign in through, runs self-hosted inside our own environment at Scaleway and is not an outside party. If an organisation links its own identity provider, that provider is the organisation's own choice.

None of these services gets to see typed text, documents, or prompts. Hetzner sees them only in working memory during detection in cloud mode, and Scaleway hosts the API that the same processing passes through.

For a formal data processing agreement, DPIA, or sub-processor list, the legal documentation is authoritative. Email trust@beesensible.eu for the current documents.