Subprocessors
Last updated: September 28, 2026
Shannon Cyber Services, LLC uses the service providers below ("subprocessors") to operate RFP Monitor. Each one processes data only to provide its service to us, under a written agreement.
"Customer Data" and "Public Data" have the meanings given in our Terms of Service.
Current subprocessors
| Vendor | Purpose | Data processed | Location | Link |
|---|---|---|---|---|
| Cloudflare, Inc. (Workers) | Runs the application and its scheduled jobs | All data that passes through the Service: requests, account and session data, Customer Data, Public Data, and application logs (IP address, browser details, URLs, errors) | Global network; each request is handled in a data center near the user | Privacy policy · DPA · Subprocessors |
| Cloudflare, Inc. (D1) | Main database | Session records, Team search-context profiles, issue reports, and the index of Public Data | Chosen by Cloudflare when the database was created. We have not set a location hint or a data jurisdiction, so the location is not limited to a particular country. | As above |
| Cloudflare, Inc. (R2) | File storage | Solicitation attachments copied from government sources (Public Data) | Chosen by Cloudflare when the bucket was created. We have not set a location hint or a data jurisdiction, so the location is not limited to a particular country. | As above |
| Cloudflare, Inc. (Browser Rendering) | Loads public government web pages to collect solicitations | Public Data only; no Customer Data | Cloudflare network | As above |
| Cloudflare, Inc. (Access) | Restricts internal operator areas to our staff | Staff identity (email address) and request details (IP address, browser) for people who reach those areas | Cloudflare network | As above |
| WorkOS, Inc. | Sign-in, Teams, single sign-on (SSO), directory sync (SCIM), invitation emails, OAuth for MCP clients, and audit logs | Name, email address, profile picture URL, Team membership and roles, sign-in method and events, IP address and browser details at sign-in, SSO and directory attributes sent by the customer's identity provider, invitation emails, audit log events | United States | Privacy policy · DPA · Subprocessors |
| OpenRouter, Inc. | Routes AI requests to model providers | Natural-language search requests; the Team's search-context profile (offerings summary, keywords, NAICS codes, preferred states); text of public solicitations and web pages; request metadata | United States | Privacy policy · Terms · Provider data policies |
AI model providers
OpenRouter sends each AI request to a provider that hosts the requested model. The provider receives the same data as OpenRouter (see the OpenRouter row above) and returns the model's response.
| Vendor | Purpose | Data processed | Location | Link |
|---|---|---|---|---|
| DeepInfra, Inc. | Runs the default model, Gemma 3 12B (google/gemma-3-12b-it). On 2026-09-28, DeepInfra was the only provider OpenRouter listed for this model. | The AI request data listed for OpenRouter | United States | Privacy policy · Data privacy |
| Google LLC | Developer of the default model. Google receives requests only if OpenRouter routes them to a Google-hosted endpoint (Google Vertex AI or Google AI Studio), or if we switch to a model that only Google hosts. | The AI request data listed for OpenRouter, when used | United States | Cloud privacy notice |
Our requests do not currently pin a provider, so OpenRouter may send a request to any provider that serves the model we use. Each provider handles requests under its own data policy, linked above. We will update this table when we change the model or the providers we allow.
Billing, email, error monitoring and analytics
The Service has built-in integrations with the providers below. Each one receives data only while its integration is switched on for the Service.
| Vendor | Purpose | Data processed | Location | Link |
|---|---|---|---|---|
| Stripe, Inc. | Subscription billing: checkout, the customer billing portal and billing events | The email address of the Team member who starts checkout, the Team's identifier, the plan, seat count and subscription status. Payment card and billing details are entered on Stripe's own pages and go to Stripe directly; we do not receive or store full card numbers. | United States | Privacy policy · Service providers |
| Resend, Inc. | Transactional email: saved-search alert digests | Recipient email address, and message content (matching public solicitations and an unsubscribe link) | United States | Privacy policy · DPA |
| Functional Software, Inc. (Sentry) | Error monitoring for the application and the data-ingest service | Error messages and stack traces, the request method and URL path, an account identifier and the Team's identifier, the software release and environment. Cookies, credentials, query strings, IP addresses and other user details are removed, and email addresses are masked, before an error report is sent. | United States | Privacy policy · Subprocessors |
| PostHog, Inc. | Product analytics | In the application: usage events (sign-up, sign-in, Team created, search performed, AI search used) with an opaque account identifier and the Team's identifier; fields that could hold personal information are dropped and IP geolocation is off. On our public website: a page-view event with the page address and a random identifier, sent by the visitor's browser without cookies, and not sent when the browser signals Global Privacy Control or Do Not Track. The browser's request also gives PostHog the visitor's IP address and browser details. | United States | Privacy policy · DPA |
Other third parties that receive limited data
These services are not used to process Customer Data. They are listed here for transparency.
| Vendor | Why it receives data | Data | Link |
|---|---|---|---|
| Google LLC (Google Fonts) | Our web pages load fonts from Google's servers | The visitor's IP address and browser details, sent by the browser when it fetches the fonts | Google Fonts privacy FAQ |
| Slack Technologies, LLC | Sends internal operational alerts to our staff, such as a data source failing | Names of government data sources and error counts; no Customer Data or user personal information | Privacy policy |
| Government data sources (SAM.gov, state, county and city portals) | We fetch public solicitations from them | Our crawler's requests only; no Customer Data | See each source |
Changes to this list
We will update this page, and email the owners of each Team, at least 30 days before a new subprocessor begins processing Customer Data. During that period a customer may object by writing to support@shannoncyber.ai, as described in its Data Processing Addendum.
Contact
Questions about our subprocessors: support@shannoncyber.ai.