Trust & security
Who else touches your data.
The third-party services limena uses to deliver the product. Each one processes some slice of your workspace data to do its job. We've written this list to be the version your procurement team can paste into a vendor questionnaire — honest about what flows where.
| Sub-processor | What they do for limena | Data they process | Region |
|---|---|---|---|
|
Supabase
supabase.com |
Hosted Postgres database, auth, file storage, and row-level security enforcement. All workspace data lives here. | User accounts and authentication tokens, workspace metadata, clients, programs, audits, findings, manual-check verdicts, operator-access logs, uploaded documents, OAuth tokens (encrypted at rest with pgsodium), LLM provider keys (encrypted at rest). | Canada Central |
|
Vercel
vercel.com |
Hosts the limena marketing site, the application (console.limena.app), and the serverless API functions. | HTTP request logs (URLs, IPs, user agents — retained 30 days), serverless function execution context (request bodies during function lifetime, not persisted). Customer audit content does not persist in Vercel beyond the function execution. | U.S. (Washington) |
|
Render
render.com |
Hosts the limena worker — the Playwright + axe-core process that loads each audited URL and runs heuristic checks. | Customer URLs (host only is logged to stdout; full URL is in process memory while the audit runs), page DOM snapshots in process memory, screenshots in process memory, audit results before they're POSTed back to Supabase. Render's stdout retention is 30 days. | U.S. (Oregon) |
|
Anthropic
anthropic.com |
LLM provider for the AI review heuristics (alt-text quality, link-text quality, heading semantics, error-message quality, language match), and for bulk user-story generation. | Extracted page elements (image alt, link text, headings, labels, body text sample) sent in the system + user prompts. Per Anthropic's API terms, prompts are not used to train models. Bring-your-own-key model: workspaces configure their own Anthropic API key. That contract is between you and Anthropic; limena holds the encrypted key only to invoke the API on your behalf. | U.S. |
|
OpenAI / Azure OpenAI
openai.com / azure.com |
Alternative LLM providers operators can configure in place of Anthropic. Same role: the AI review heuristics and bulk user-story generation. | Same payload as Anthropic — extracted page elements. Same bring-your-own-key model: your contract with the provider, limena holds the encrypted key. | U.S. (varies) |
|
Google PageSpeed Insights
developers.google.com/speed |
Lighthouse audit runner. Called from the limena API when an operator runs a Lighthouse check on an audit. | The audited URL. Google's API returns Lighthouse scores (Performance, Accessibility, Best Practices, SEO) which limena stores back to the audit row. | Global (Google) |
|
Atlassian (Jira) /
Linear
atlassian.com / linear.app |
Optional tracker integrations. Used only when a workspace operator connects an issue tracker and explicitly pushes a finding to it. | The finding title, description, and remediation user-story for each pushed issue. The OAuth access token to your tracker workspace is stored encrypted at rest. Nothing is pushed without an explicit operator action. | Per provider |
What's notably not on this list: Stripe (limena's billing isn't live yet — when it is, Stripe will join this list and we'll ship a DPA addendum), AWS / Cloudflare / similar (we don't have direct contracts with them; where they're underlying providers for our sub-processors above, that's covered by the sub-processor's own terms), advertising or analytics platforms (we don't use any), and training-data harvesters (we don't sell, share, or transmit customer data to anyone outside this list for any purpose).
Material changes
When we add, remove, or materially change a sub-processor (e.g. one starts processing a different category of data, or moves to a new region), we'll update this page and email the workspace owner. Customers on paid plans can subscribe to changes by emailing legal@limena.app to be added to the notification list — you'll get advance notice (typically 30 days) before a new sub-processor begins handling your data, with an opt-out path if you can't accept the addition.
Data residency & transfers
limena's primary database and storage are hosted in Canada Central (Supabase region). Customer data is replicated within that region for durability and does not leave it for primary storage purposes.
Several sub-processors operate from the United States (Vercel, Render, Anthropic, OpenAI, Google PSI). When customer data flows to those providers — request handling, serverless function execution, audit worker runs, LLM calls, Lighthouse runs — that constitutes a cross-border transfer to the U.S. Where contracts are available, we sign Standard Contractual Clauses (SCCs) for EU-residency customers via DPAs.
DPA
Customers on paid plans can sign a Data Processing Addendum based on the GDPR / UK GDPR / Quebec Law 25 / PIPEDA standard. Email legal@limena.app and we'll send the template.
Last reviewed: 2026-06-17. Maintained by Ryan Short, limena founder. Questions? legal@limena.app.