Scandrix
Transparency · Last updated March 2026

Subprocessors.

ScanDrix acts as a processor for customer data. These are the vendors we use to deliver the service. Your source code is not shared with any of them — see the zero code retention guarantee in our privacy policy.

Razorpay

India

Purpose

Subscription billing and payment processing

Data shared

Billing name, billing email, plan, payment identifiers

Purpose

Product analytics (opt-in, consent-gated)

Data shared

Page views, referrer, coarse device and country, session events

OpenRouter

United States

Purpose

Model inference for the website chat assistant

Data shared

Chat message text only, with secrets redacted before sending

Purpose

Fallback model inference for the website chat assistant

Data shared

Chat message text only, with secrets redacted before sending

Purpose

Fallback model inference for the website chat assistant

Data shared

Chat message text only, with secrets redacted before sending

Purpose

Repository star counts and public pull-request metadata for the live PR preview demo

Data shared

Public repository metadata only — no customer source code

Self-hosted deployments

Customers on the self-hosted VPC or on-premise plan run the entire stack — API, queue, AST workers, and model endpoint — inside their own network. In that configuration none of the vendors above process their code, and any model provider is one they control themselves.

Changes to this list

We notify customers by email before adding a new subprocessor that will handle customer personal data, giving notice of the intended change. Existing customers may object within 30 days, and we will work with them on an alternative arrangement.

Need something not on this list?

If your compliance review requires a different arrangement — a specific region, a contractual DPA, or removal of a vendor — tell us and we will work through it.

Contact our security team