Subprocessors
Last updated: September 21, 2026
WebDecoy LLC uses the providers below to run its service. This page lists them all, what each one does, and what data reaches it. It is referenced by our Data Processing Agreement and our Privacy Policy.
To be notified before this list changes, email [email protected] and we will add you to the notification list described in section 7 of the DPA.
Infrastructure and core services
These are required. The service cannot run without them.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Railway | Hosts the API, dashboard, rule engine and the primary database | All account data and all stored detection records | United States |
| Amazon Web Services (EC2) | Hosts the ingest service that receives detection events and serves decoys | Visitor IP address, user agent, request headers, TLS fingerprint | US East (Ohio) |
| Amazon Web Services (SES) | Sends transactional and digest email | Account holder email address and name | US East (N. Virginia) |
| Cloudflare | DNS, CDN, the script served to customer sites, and edge sensors | Visitor IP address and user agent in transit at the edge | Global edge network |
| Auth0 (Okta) | Sign-in for the dashboard | Account holder email, name, IP address, sign-in events | United States |
| Stripe | Subscription billing and payments | Billing name, address, payment method. Card details go to Stripe directly and never reach our servers | United States |
Loaded in the dashboard and on our sites
These receive the IP address and browser details of people who visit our own properties. They do not receive detection data.
| Provider | Purpose | Where |
|---|---|---|
| Google Fonts | Typeface and icon files | Dashboard |
| jsDelivr | Map boundary data for the geographic chart | Dashboard |
| Google Analytics | Documentation site usage statistics | docs.webdecoy.com |
| HubSpot | Support request form, loaded only when you open it | Dashboard |
Enrichment providers
These add context to a detection. Each is used only where the plan and configuration enable it, and the first two receive an IP address only, with no other visitor data.
| Provider | Purpose | Data processed |
|---|---|---|
| AbuseIPDB | IP reputation scoring | Visitor IP address |
| vpnapi.io | VPN, proxy and Tor detection | Visitor IP address |
| Google (Gemini) | Written explanation of a single detection, generated only when you click the button | The detection's signals, including IP address and user agent |
| TypeSafe | Classifying an actor's browsing pattern, on request | Request paths and relative timings only. IP addresses and user agents are removed first |
| Cloudflare Turnstile | Human verification challenge, where you enable it | Challenge token and visitor IP address |
| MaxMind GeoLite2 | Country and city lookup | None. The database runs on our own server and no data is sent to MaxMind |
Destinations you choose
These are not our subprocessors. They are systems you connect, and detection data reaches them because you told us to send it. You control the relationship and the region.
- Cloudflare WAF, AWS WAF and Fastly, for pushing confirmed attackers to your own edge
- Datadog, Splunk and CrowdStrike, for forwarding detection events to your logging or security tooling
- Slack and custom webhooks, for notifications
- Vercel, Netlify and Shopify, where you install a WebDecoy sensor on their platform
Providers that receive no personal data
- Let's Encrypt, which issues TLS certificates for custom domains and receives domain names only
- GitHub, which stores our source code and container images
- Cloudflare R2, which stores downloadable plugin files
What we do not use
We run no advertising networks, no session recording, no product analytics on the dashboard, and no third-party error tracking. Our customer list is not shared with anyone.
Questions
Email [email protected]. If you need this list as a signed attachment to a vendor review, we will provide one.