Legal · Version 1.0 · Effective 27 July 2026
Sub-processors
Every third party that touches customer data, what it does, and what it sees.
This is the whole list. Four companies. If it changes we update this page and email account owners at least 30 days before the new sub-processor starts, so you have time to object.
| Sub-processor | What it does | Where | What it can see |
|---|---|---|---|
| Vercel Inc. | Hosts the web application and its server functions | United States | Any data passing through a page or an API request while it is being served |
| Railway Corporation | Runs the firmware analysis engine, the PostgreSQL database and the scheduled jobs | United States, US West | All stored customer data, and firmware images for the life of a scan |
| Dodo Payments | Merchant of record: checkout, payment, invoicing, VAT and reverse charge | See their own policies | Billing name, address, tax identifier and payment method. We never receive card details |
| Zoho Corporation | Sends transactional email: sign-in links, vulnerability alerts, account notices | India region | Recipient email address and the content of the message sent |
A note on Dodo Payments
Dodo Payments does not name a single registered entity or jurisdiction in its published privacy policy, so we are not going to state one on their behalf. They are the merchant of record for your purchase, which means they are the seller for that transaction and their own terms govern the payment relationship. We hold their customer identifier and subscription identifier and nothing else about your payment.
What is not on this list
No analytics provider, no advertising network, no customer data platform, no CRM, no session recorder, no support chat widget and no email marketing tool. None of those exists on this product, so none of them appears here.
Public vulnerability sources are not sub-processors and are not on this list, because nothing about you goes to them. We query NVD, CISA KEV, FIRST EPSS, the GitHub Advisory Database and ENISA EUVD by component name and version. Those requests say "openssl 3.0.11" and never say who asked.
Objecting to a change
Reply to the notice, or email hello@synthworx.com, within 30 days. If we cannot resolve your objection you can cancel and we refund the unused part of the period you paid for.
Version history
| Version | Date | What changed |
|---|---|---|
| 1.0 | 27 July 2026 | First published. |
DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America. Questions about this document go to hello@synthworx.com and a person answers.
The rest of the policies
The contract between you and DNS Ventures LLC for CRA Kit. What we do, what we do not do, what you pay, and who is responsible for what.
Refund and cancellation policyCancel from a screen, keep what you paid for until the period ends, and the cases where we give money back.
Privacy policyWhat personal data CRA Kit holds, why, for how long, who else touches it, and how to get it back or get it deleted.
Data processing addendumThe Article 28 GDPR processor terms, already in force for every customer. No signature needed, no procurement queue to join.
Acceptable use policyWhat you may point the firmware analysis engine at, and the small number of things that get an account suspended.