1. Supplier inventory
| Supplier | Purpose | Data it can access | Location | Status |
|---|---|---|---|---|
| Hostinger | VPS hosting (compute, disk, network, datacenter) | All platform data, logs and backups | Datacenter location to be confirmed | Active - subprocessor |
| Resend | Transactional e-mail (watch-list confirmation and vendor alerts) | Recipient e-mail, name and message content | Region sa-east-1 (São Paulo) | Active - subprocessor |
| GoDaddy (Titan Mail) | Company mailbox contato@semantiqwall.com | Messages sent to us (support, privacy and security requests) | To be confirmed | Active - subprocessor |
| GitHub | Private source code repository; deploy key; SemantiqWall GitHub App for customers who install it | Our code; for App users, the files the customer allows and the pull requests we open | United States | Active - supplier; subprocessor only for GitHub App users |
| Anthropic | AI provider for optional case triage and remediation proposals | Case summary and evidence text, agent description, up to 4 files of the customer's code | United States | Optional - used only when configured |
| Meta (WhatsApp Cloud API) | Optional approval messages | Approver phone number, approval message | Meta infrastructure | Disabled |
| Certificate authorities (ACME, via Caddy) | TLS certificates | Domain names only | - | Active |
| Domain registrar | semantiqwall.com registration and DNS | DNS records | - | Registrar to be confirmed |
| Open-source packages (Composer, npm) | Application and SDK dependencies | None at runtime beyond the code itself | - | Pinned in lock files |
The public list of subprocessors is kept in the privacy policy and updated before a new subprocessor starts receiving personal data. Customers can object by writing to contato@semantiqwall.com.
2. Shared responsibility with suppliers
| Area | Supplier is responsible for | SemantiqWall is responsible for |
|---|---|---|
| Hosting (Hostinger) | Datacenter physical and environmental security, hardware, hypervisor, network up to the VPS, media disposal | Everything inside the VPS: OS hardening and updates, firewall, SSH, application, database, backups, encryption, monitoring |
| E-mail (Resend, Titan) | Delivery infrastructure and security of their platforms | Account MFA, API key protection, content we send, domain authentication records |
| Code hosting (GitHub) | Platform security | Repository access, MFA, deploy keys, App permissions (least privilege: contents, pull requests, metadata) |
| AI provider | Model hosting and their data handling commitments | Sending only the minimum, treating output as untrusted, never letting AI decide allow/deny, turning the feature off if terms change |
3. Selecting a new supplier
Before a supplier receives customer or personal data, the Founder checks and records in the security register:
- purpose and the minimum data needed;
- security evidence - SOC 2 or ISO 27001 report or a public security page;
- data processing terms, including international transfer clauses when outside Brazil, breach notification and subprocessors;
- data location and retention;
- MFA available on the account;
- how to leave: export and deletion.
A supplier handling customer data with no security evidence needs an exception (policy 00).
4. Requirements for suppliers
Suppliers must keep customer data confidential, use it only to provide their service to SemantiqWall, notify us of breaches affecting our data, and delete it at the end of the service. For today's suppliers these obligations come from their standard online terms, which are accepted rather than negotiated.
5. Review
- Annually, and when a supplier changes its terms, location or ownership or has a breach: re-check section 3, confirm MFA on our account, and record the review.
- Commitment - first formal review of every active supplier: obtain Hostinger's datacenter location and security attestation (ISO 27001 or SOC 2) and media disposal statement, and archive the data processing terms of Hostinger, Resend, GoDaddy, GitHub and Anthropic (owner: Founder, target 2026-10-31).
- Supplier incidents follow policy 05.
6. Software supply chain
- Dependencies are pinned (
composer.lock, SDK lock files) and come only from official registries. - The GitHub App requests only the permissions it needs, and SemantiqWall never merges pull requests in customers' repositories.
- Commitments: dependency alerts (target 2026-10-15),
composer auditin CI and deploy (target 2026-11-30) and a Software Bill of Materials per release (target 2026-12-31), as set in policies 03 and 07.