Subprocessors
A service appears in this table if Ledger sends data to it when it is enabled. Where a provider has not been confirmed yet, the row says so rather than naming one; the trust page in the app is where confirmed providers are published.
| Subprocessor | Role and data it receives |
|---|---|
| Cloud infrastructure provider (not yet confirmed) | Application hosting, the managed key store and object storage (see data retention). Receives what Ledger stores there, with connection credentials only in encrypted form. |
| Managed database provider (not yet confirmed) | Primary database hosting. Receives everything Ledger stores in its database, with connection credentials only in encrypted form. |
| Email delivery (SMTP) provider (not yet confirmed) | Scheduled-report email: recipient addresses and the content of the report. Only sends data when scheduled reports are configured. |
| WorkOS | Sign-in and authentication: user email addresses and session information. |
| Sentry | Error reporting: technical error details and request context. Every event is scrubbed of credential-like values (tokens, keys, passwords) inside Ledger before it leaves, and error reporting only sends data when it has been switched on for the deployment. See data retention. |
| Resend | Transactional email delivery, such as the weekly health digest: recipient addresses and the content of the email. Only sends data when email delivery has been configured for the deployment. |
| PostHog | Product analytics. Pending confirmation: whether PostHog is a cloud service (a subprocessor) or self-hosted (not a subprocessor) has not been confirmed, so no claim is made either way. |
Beyond these, data goes only to services you configure yourself, such as the address of your own webhook receiver. Every stored connection credential is encrypted per customer before any of the above sees it. See data retention for how data is kept and removed and the questionnaire for the wider security posture.