EnjiEnji Guard
ProblemHow it worksRunbooksComparisonFAQ
B2B demoStart free demo
All legal pages
Privacy Terms Security & Trust AI Data Use GitHub App Authorized Testing Data Retention Subprocessors Vulnerability Disclosure

Subprocessors

Questions: [email protected].

Enji Guard uses subprocessors to provide, secure, and support the service. Subprocessors may process personal data, Customer Content, or technical data only for the purposes described in the Privacy Policy and applicable agreements.

No additional production subprocessor categories are expected for the current service beyond repository hosting, sign-in, approved AI/coding providers, transactional email, feedback/support delivery, CDN/security edge, and Google-hosted application infrastructure. Database, object-storage, observability, logging, and backup/restore components are open-source or self-hosted technologies rather than separate third-party subprocessor vendors in this policy.

Self-serve billing and payment processing are planned but not part of this subprocessor list. Do not list a billing or payment processor until a production billing flow is enabled.

Subprocessor List

SubprocessorPurposeData categoriesCustomer code/content?Status
GitHubRepository hosting, GitHub App install, repo verification, issues, pull requests, commentsRepository metadata, code, issues, PRs, commentsYes, for connected repositoriesGitHub App manifest uses contents/issues/pull requests write and metadata read
Google / Google CloudOAuth sign-in and application hostingAccount identity, application data, logs, request metadataPossible through hosting infrastructureProduction hosting provider
OpenAIAI model API or business/developer AI servicesTask context, code snippets, reports, logs, outputsYes, depending on selected routeApproved AI provider
Anthropic, PBCAI model API and related commercial API routesTask context, code snippets, reports, logs, outputsYes, depending on selected routeApproved AI provider
MOONSHOT AI PTE. LTD.Kimi OpenPlatform APITask context, code snippets, reports, logs, outputsYes, depending on selected routeApproved AI provider; Singapore-operated route
ANOMALY INNOVATIONS, INC.OpenCode / OpenCode Enterprise / OpenCode Zen, depending on production configurationCoding-agent context, share content if hosted sharing is enabledPossibleApproved coding tool provider
Anysphere, Inc.Cursor platform, CLI, agents, or related Cursor services if used in production workflowsCoding-agent context, prompts, code snippets, outputsPossibleApproved coding tool provider
ResendTransactional emailRecipient email, subject, rendered email body, delivery metadataUsually no code; reports may be linkedProduction transactional email provider
Third-party communication/support toolingFeedback handlingFeedback text, user email, screenshotsPossible if screenshots contain contentProduction feedback processing category
CloudflareTLS, tunnel/CDN/security edge if usedIP address, request metadata, headersNo intended code processingProduction CDN/security edge provider
Open-source/self-hosted infrastructure technologiesDatabase, object storage, observability, logging, and backup/restore components operated by Enji.aiAccount data, metadata, reports, logs, settings, task outputsPossibleNot separate third-party subprocessor vendors

AI Provider Rule

Enji Guard does not train or operate its own foundation models.

Customer code and task data should be processed only by approved third-party AI model providers and coding tool providers under their public data-use and retention terms unless a separate written agreement says otherwise.

The approved AI/coding provider list for this policy is OpenAI, Anthropic, MOONSHOT AI PTE. LTD. for Kimi OpenPlatform, ANOMALY INNOVATIONS, INC. for OpenCode, and Anysphere, Inc. for Cursor.

Customers with strict provider, residency, or retention requirements can contract with Enji.ai for an on-premises or customer-controlled deployment. For that deployment model, the customer is responsible for selecting, approving, configuring, and monitoring the AI/coding providers connected to the customer’s environment.

Subprocessor Change Notice

This policy does not publish a separate subprocessor-change notice workflow or DPA terms. Customer-specific commitments can be added later through signed agreements.

© 2026 Enji.ai · All rights reserved
PrivacyTermsSecurityAI Data UseAll legal pages