Trust · Draft

Sheet
T-300
Set
Trust
Status
Draft

Subprocessors

The third parties that process data for Fleet or for this site, what each one receives, and where, as established by a code and configuration audit on 27 September 2026.

T-300TrustDraft

Who processes what

Each row comes from the audit of the Fleet code and its deployment configuration, with the file that shows the connection. Where a processor's location or retention could not be established from what we control, the cell says unknown rather than a guess.

ProcessorPurposeDataLocation
Supabase Identity provider (Auth, OAuth 2.1 server) and the operations database for the hosted service. Account email and user id, organization and membership records, hashed session and invitation tokens, job records and events, spend reservations, hashed OpenRouter key ids, learning records. US East (project verified as us-east-1)
Railway Hosting for the API and the two private services, their private network, TLS termination, and the sandbox VMs that run validations. Everything the services hold in memory or on their disks, including the repository mirror and receipt files on the validator; platform request logs (their content and retention are Railway's). unknown (region not verified for this project)
GitHub Source of the repositories Fleet verifies; the check-runs Fleet posts. Repository contents read with a read-only token; check-run summaries with counts and ids only. GitHub also receives the GitHub App installation on your organization. GitHub's infrastructure (United States and elsewhere, per GitHub)
OpenRouter, and the model providers it routes to Model calls made by jobs (never by the API itself), each under a per-job key capped at the job's budget; key management and usage for settlement. Task text and the repository content a job needs, sent with data collection set to deny on every request; usage and cost per key. unknown (provider-side retention and location are OpenRouter's and each provider's)
jsDelivr Serves the pinned supabase-js module to the OAuth consent page (which the Fleet API hosts). The browser's request for the script (IP address and user agent reach the CDN); no Fleet data. global CDN
Resend Email for access and support requests sent from this site, through the Oracis intake API: the internal alert to Oracis, the acknowledgement to you, and delivery events back to us. The form fields you submit (name, email, organization, message) for the alert; your name and address for the acknowledgement; delivery, bounce and complaint events for the messages we send. unknown (Resend's infrastructure)
Cloudflare DNS for oracis.ai and its subdomains, including fleet.oracis.ai. Traffic is not proxied through Cloudflare. DNS queries for the fleet.oracis.ai name only; no page, form or API traffic passes through Cloudflare. global

Changes

A processor is added to this page before it receives any data, and the change is noted in the page's revision in the footer index. Members of a pilot organization are told by email when a processor that receives their organization's data is added.

Not used

No analytics, advertising, session-replay or error-reporting service processes data for the hosted service or this site. Fleet's own local tooling reaches other services (for example a model marketplace) but the hosted service you connect to does not.