AcquiCode diligence

Subprocessors

Last updated 28 September 2026.

The third parties that can receive data from AcquiCode at acquicode.infinityore.com. This list is generated from how this deployment is configured, so it shows what is actually in use rather than what might be.

WhoPurposeDataWhen
Railway (United States)Hosting the application, database and storageAll service data, encrypted at rest by the applicationAlways
GitLab (gitlab.com or your self-managed instance)Reading GitLab projects you connectRepository contents fetched with your project access tokenOnly for GitLab projects you connect
t3.storageapi.devStoring dossiers and pending uploadsEncrypted objects only; keys never leave the applicationAlways
OSV.dev (Google)Known-vulnerability lookupNames and versions of public open-source packages only; never private packages or codeOnly if dependency checks are enabled for your organisation
npm registry and PyPILicense and release-date lookupNames of public open-source packages onlyOnly if dependency checks are enabled for your organisation

No language-model, analytics or advertising provider receives data from this service.