Trust & security

Who else touches your data.

The third-party services limena uses to deliver the product. Each one processes some slice of your workspace data to do its job. We've written this list to be the version your procurement team can paste into a vendor questionnaire — honest about what flows where.

Sub-processor What they do for limena Data they process Region
Supabase

supabase.com

Hosted Postgres database, auth, file storage, and row-level security enforcement. All workspace data lives here. User accounts and authentication tokens, workspace metadata, clients, programs, audits, findings, manual-check verdicts, operator-access logs, uploaded documents, OAuth tokens (encrypted at rest with pgsodium), LLM provider keys (encrypted at rest). Canada Central
Vercel

vercel.com

Hosts the limena marketing site, the application (console.limena.app), and the serverless API functions. HTTP request logs (URLs, IPs, user agents — retained 30 days), serverless function execution context (request bodies during function lifetime, not persisted). Customer audit content does not persist in Vercel beyond the function execution. U.S. (Washington)
Render

render.com

Hosts the limena worker — the Playwright + axe-core process that loads each audited URL and runs heuristic checks. Customer URLs (host only is logged to stdout; full URL is in process memory while the audit runs), page DOM snapshots in process memory, screenshots in process memory, audit results before they're POSTed back to Supabase. Render's stdout retention is 30 days. U.S. (Oregon)
Anthropic

anthropic.com

LLM provider for the AI review heuristics (alt-text quality, link-text quality, heading semantics, error-message quality, language match), and for bulk user-story generation. Extracted page elements (image alt, link text, headings, labels, body text sample) sent in the system + user prompts. Per Anthropic's API terms, prompts are not used to train models. Bring-your-own-key model: workspaces configure their own Anthropic API key. That contract is between you and Anthropic; limena holds the encrypted key only to invoke the API on your behalf. U.S.
OpenAI / Azure OpenAI

openai.com / azure.com

Alternative LLM providers operators can configure in place of Anthropic. Same role: the AI review heuristics and bulk user-story generation. Same payload as Anthropic — extracted page elements. Same bring-your-own-key model: your contract with the provider, limena holds the encrypted key. U.S. (varies)
Google PageSpeed Insights

developers.google.com/speed

Lighthouse audit runner. Called from the limena API when an operator runs a Lighthouse check on an audit. The audited URL. Google's API returns Lighthouse scores (Performance, Accessibility, Best Practices, SEO) which limena stores back to the audit row. Global (Google)
Atlassian (Jira) / Linear

atlassian.com / linear.app

Optional tracker integrations. Used only when a workspace operator connects an issue tracker and explicitly pushes a finding to it. The finding title, description, and remediation user-story for each pushed issue. The OAuth access token to your tracker workspace is stored encrypted at rest. Nothing is pushed without an explicit operator action. Per provider

What's notably not on this list: Stripe (limena's billing isn't live yet — when it is, Stripe will join this list and we'll ship a DPA addendum), AWS / Cloudflare / similar (we don't have direct contracts with them; where they're underlying providers for our sub-processors above, that's covered by the sub-processor's own terms), advertising or analytics platforms (we don't use any), and training-data harvesters (we don't sell, share, or transmit customer data to anyone outside this list for any purpose).

Material changes

When we add, remove, or materially change a sub-processor (e.g. one starts processing a different category of data, or moves to a new region), we'll update this page and email the workspace owner. Customers on paid plans can subscribe to changes by emailing legal@limena.app to be added to the notification list — you'll get advance notice (typically 30 days) before a new sub-processor begins handling your data, with an opt-out path if you can't accept the addition.

Data residency & transfers

limena's primary database and storage are hosted in Canada Central (Supabase region). Customer data is replicated within that region for durability and does not leave it for primary storage purposes.

Several sub-processors operate from the United States (Vercel, Render, Anthropic, OpenAI, Google PSI). When customer data flows to those providers — request handling, serverless function execution, audit worker runs, LLM calls, Lighthouse runs — that constitutes a cross-border transfer to the U.S. Where contracts are available, we sign Standard Contractual Clauses (SCCs) for EU-residency customers via DPAs.

DPA

Customers on paid plans can sign a Data Processing Addendum based on the GDPR / UK GDPR / Quebec Law 25 / PIPEDA standard. Email legal@limena.app and we'll send the template.

Last reviewed: 2026-06-17. Maintained by Ryan Short, limena founder. Questions? legal@limena.app.