Subprocessors
Last updated 28 September 2026.
The third parties that can receive data from AcquiCode at acquicode.infinityore.com. This list is generated from how this deployment is configured, so it shows what is actually in use rather than what might be.
| Who | Purpose | Data | When |
|---|---|---|---|
| Railway (United States) | Hosting the application, database and storage | All service data, encrypted at rest by the application | Always |
| GitLab (gitlab.com or your self-managed instance) | Reading GitLab projects you connect | Repository contents fetched with your project access token | Only for GitLab projects you connect |
| t3.storageapi.dev | Storing dossiers and pending uploads | Encrypted objects only; keys never leave the application | Always |
| OSV.dev (Google) | Known-vulnerability lookup | Names and versions of public open-source packages only; never private packages or code | Only if dependency checks are enabled for your organisation |
| npm registry and PyPI | License and release-date lookup | Names of public open-source packages only | Only if dependency checks are enabled for your organisation |
No language-model, analytics or advertising provider receives data from this service.