WebDecoy LLC uses the providers below to run its service. This page lists them all, what each one does, and what data reaches it. It is referenced by our Data Processing Agreement and our Privacy Policy.

To be notified before this list changes, email [email protected] and we will add you to the notification list described in section 7 of the DPA.

Infrastructure and core services

These are required. The service cannot run without them.

ProviderPurposeData processedLocation
RailwayHosts the API, dashboard, rule engine and the primary databaseAll account data and all stored detection recordsUnited States
Amazon Web Services (EC2)Hosts the ingest service that receives detection events and serves decoysVisitor IP address, user agent, request headers, TLS fingerprintUS East (Ohio)
Amazon Web Services (SES)Sends transactional and digest emailAccount holder email address and nameUS East (N. Virginia)
CloudflareDNS, CDN, the script served to customer sites, and edge sensorsVisitor IP address and user agent in transit at the edgeGlobal edge network
Auth0 (Okta)Sign-in for the dashboardAccount holder email, name, IP address, sign-in eventsUnited States
StripeSubscription billing and paymentsBilling name, address, payment method. Card details go to Stripe directly and never reach our serversUnited States

Loaded in the dashboard and on our sites

These receive the IP address and browser details of people who visit our own properties. They do not receive detection data.

ProviderPurposeWhere
Google FontsTypeface and icon filesDashboard
jsDelivrMap boundary data for the geographic chartDashboard
Google AnalyticsDocumentation site usage statisticsdocs.webdecoy.com
HubSpotSupport request form, loaded only when you open itDashboard

Enrichment providers

These add context to a detection. Each is used only where the plan and configuration enable it, and the first two receive an IP address only, with no other visitor data.

ProviderPurposeData processed
AbuseIPDBIP reputation scoringVisitor IP address
vpnapi.ioVPN, proxy and Tor detectionVisitor IP address
Google (Gemini)Written explanation of a single detection, generated only when you click the buttonThe detection's signals, including IP address and user agent
TypeSafeClassifying an actor's browsing pattern, on requestRequest paths and relative timings only. IP addresses and user agents are removed first
Cloudflare TurnstileHuman verification challenge, where you enable itChallenge token and visitor IP address
MaxMind GeoLite2Country and city lookupNone. The database runs on our own server and no data is sent to MaxMind

Destinations you choose

These are not our subprocessors. They are systems you connect, and detection data reaches them because you told us to send it. You control the relationship and the region.

  • Cloudflare WAF, AWS WAF and Fastly, for pushing confirmed attackers to your own edge
  • Datadog, Splunk and CrowdStrike, for forwarding detection events to your logging or security tooling
  • Slack and custom webhooks, for notifications
  • Vercel, Netlify and Shopify, where you install a WebDecoy sensor on their platform

Providers that receive no personal data

  • Let's Encrypt, which issues TLS certificates for custom domains and receives domain names only
  • GitHub, which stores our source code and container images
  • Cloudflare R2, which stores downloadable plugin files

What we do not use

We run no advertising networks, no session recording, no product analytics on the dashboard, and no third-party error tracking. Our customer list is not shared with anyone.

Questions

Email [email protected]. If you need this list as a signed attachment to a vendor review, we will provide one.