To run Mezbano we rely on a small number of third-party providers (“subprocessors”) that process data on our behalf. The table includes fixed provider services and the deployment-selected destination categories present in the code.
Optional providers operate only when their integration is configured. They process data only when the related feature is used.
Provider brand names do not establish the contracting legal entity or all processing locations; the deployment operator must verify those details against the live account and applicable data processing agreement. The two operator-selected rows disclose optional capabilities whose provider identity cannot be derived from this repository. Before either is enabled, the operator must publish its legal name, region, purpose, terms, and activation status. A generic row is not sufficient as the final contractual disclosure.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Cloudflare | Cloud hosting, application runtime, database, file storage, and optional Turnstile abuse protection | Application data entered into the service, uploaded files, and request/security metadata; a Turnstile response token and visitor IP address are sent for challenge verification when that integration is enabled | Global network; contracting entity and any data-localization configuration are deployment-specific |
| Resend (Plus Five Five, Inc.) | Transactional email delivery when email is configured | Recipient email address and message content for account and workspace emails (invitations, password resets, and notifications) | Provider account and sending-region configuration are deployment-specific and must be verified by the operator |
| Stripe | Subscription checkout, payment management, invoicing, and billing reconciliation when Stripe is configured | Billing contact details, Stripe customer and subscription references, and payment details entered directly in Stripe-hosted Checkout or the Customer Portal. Mezbano does not store full card details. | Global; contracting entity and account configuration are customer-specific |
| Operator-selected offsite storage provider | Optional cross-provider recovery storage when the offsite S3-compatible integration is completely configured | Completed database backup generations, archived audit records, and claimed attachment bytes and recovery metadata | Deployment-specific; must be published before activation |
| Operator-selected incident alert receiver | Optional operational incident notification when an alert webhook endpoint is configured | Service name, deployment environment, severity, generic error code and class, correlation request ID, parameterized route ID, HTTP status when available, and timestamp. Raw error messages, stack traces, causes, provider bodies, interpolated paths, user IDs, and email fields are not sent | Deployment-specific; must be published before activation |
Customer-directed identity providers
A workspace can configure its own OIDC or SAML identity provider for single sign-on. That provider receives the identity and authentication-flow data needed to complete the customer’s directed sign-in. Because Mezbano does not select that provider, it is not listed above as a Mezbano-appointed subprocessor; the customer must assess its own provider relationship.
Changes to this list
We will update this page before a new fixed or deployment-selected subprocessor begins processing customer data and give reasonable advance notice — at least 30 days where practical and subject to the applicable customer agreement — so customers can review the change. Questions? Email support@mezbano.com.
See also our security posture and privacy policy.