Subprocessors

Who else touches your data.

To deliver Agent Etna we rely on a small set of third-party services for inference, sandbox execution, hosting, authentication, and billing. This page lists every one of them, what they process on our behalf, and where. It updates when the stack changes.

Current subprocessors

ServicePurposeData processedRegion
e2b Throwaway sandbox VMs that build and run a private copy of your agent during a cycle. A clone of your repository at runtime and the secrets you've granted access to. Both are scoped to the sandbox's lifetime and reclaimed when the cycle ends. United States
GitHub OAuth authentication and repository access for the agents you connect. OAuth identity (email, username, avatar), repository contents you grant access to, and the commits/PRs Etna opens on your behalf. United States
Render Hosting for the Agent Etna application servers. HTTP request metadata, application logs, and the encrypted at-rest data Etna persists. United States
Managed PostgreSQL (Neon) Durable storage for agent configuration, calibrations, cycle results, and user state. Account records, agent configs (secrets encrypted), capability maps, growth history, and audit events. United States
Stripe Payment processing for paid plans, wallet top-ups, and invoicing. Billing identity, payment-method tokens (Stripe holds card data — Etna never sees it), invoices, and transaction history. United States
Amazon Web Services Durable object storage (S3) for behavior logs, datasets, and evaluation artifacts. Simulation artifacts and behavior logs written by the Service. Encrypted at rest; the bucket blocks all public access. Germany (eu-central-1)
Sentry Error monitoring, so failures reach us before a user has to report them. Error events and stack traces from our servers. Default PII capture is off. European Union
PostHog Product analytics — which features get used, where the funnel loses people. Usage events and page views, collected only with your cookie consent. United States
Google OAuth authentication ("Sign in with Google"). OAuth identity only — email, name, avatar. Nothing else is requested or granted. United States
Resend Transactional email — sign-in links, account-deletion notices, regression alerts. Your email address and the content of the transactional messages we send you. United States

Last updated: 2026-07-29. We notify enterprise customers in advance of material changes to this list per their contract.

Your LLM provider — not our subprocessor

Every plan runs on the LLM key you bring, so inference goes to the provider you chose under your own agreement with them — that's why no LLM provider appears in the table above. Worth knowing when you pick a key: Zhipu, Alibaba, Moonshot, and MiniMax process in China. We keep no persistent copy of the inference traffic beyond aggregated usage stats.

What this list does not cover

The agent you connect may itself call other services (a database, a chat platform, third-party tools). Those are your subprocessors, not ours — Etna doesn't insert itself between your agent and the services it already calls. If your agent's secrets manager is Doppler, Vault, Render, Infisical, AWS, GCP, or Azure, we pull keys from there at runtime so they stay in your platform of choice and rotate where you already manage them.

Subscribe to changes

To be notified before this list changes — required by some procurement reviews — email contact@agentetna.com with the agents you operate and we'll add you to the advance-notice roster.

Need a DPA or vendor questionnaire?

Send the form your way — we'll fill it in and return signed copies.

Contact us