Vallum
TRAFFIC PATH

In the protected traffic path

These providers carry or can interrupt protected requests. An outage here consumes availability under the service level agreement, and Vallum owns it — provider failure is not an excluded event.

Render

Hosts the Vallum proxy, its managed database, and its cache. Every protected request is served from Render compute.

Status page
SUPPLIES
  • Proxy edge and management API (containers)
  • Managed PostgreSQL 16 — policy, tenants, audit trail
  • Managed Key Value (Redis) — sessions, fingerprints, rate limits
  • Demo origin used by the public product demo
Region
Virginia, United States (us-east)
In use since
2026
Data handled
Request metadata, session and fingerprint state, tenant configuration, and the audit trail.
Provider
render.com
SUPPORTING

Supporting services

These providers sit beside the traffic path. If one of them is down you may not be able to sign in to the console or book a call, but protected traffic keeps flowing to your origin under the policy already deployed.

Vercel

Hosts the customer console, the staff surface, and the marketing site. Protected traffic reaches your origin through the proxy without passing here.

Status page
SUPPLIES
  • Customer console and staff surface
  • Marketing site and documentation
  • TLS termination and edge caching for those surfaces
Region
Global edge network, United States primary region
In use since
2026
Data handled
Console session cookies, request logs for the console and website, and form submissions in transit.
Provider
vercel.com

Clerk

Identity for the customer console and the staff surface, including organization membership and invitations.

Status page
SUPPLIES
  • Console and staff authentication
  • Organizations, roles, and owner sign-up links
  • Authentication email delivery
Region
United States
In use since
2026
Data handled
Names, work email addresses, organization membership, and session records for console users.
Provider
clerk.com

Cal.com

Scheduling for the security-assessment call embedded on the marketing site.

Status page
SUPPLIES
  • Booking embed on the Book a call page
Region
United States and European Union
In use since
2026
Data handled
Name, email, and meeting details supplied by someone booking a call.
Provider
cal.com

How this list changes

A provider is added here before it carries production traffic, and customers on a paid plan are notified at least thirty days before a new subprocessor begins handling their data — enough time to raise an objection under your agreement. Removals are published in the same place.

Availability commitments, credits, and how downtime is measured live in the Service Level Agreement. How data is handled is described in the Privacy Policy.