Vertrouwenscentrum
Wie gegevens voor ons verwerkt.
12 diensten vandaag in gebruik. Elke rij vermeldt wat de dienst ontvangt en welke code het verstuurt, zodat u het kunt controleren.
Netlify, Inc.
Hosts this site and its serverless functions; Netlify Blobs is the primary key-value store for accounts, subscriptions, seat-report ledgers, audits, policies and vault documents.
Ontvangt: Everything the app persists outside Convex. The store-by-store inventory is in lib/data-stores.ts.
bron:
lib/blobs.ts, netlify.tomlConvex, Inc.
System of record for user accounts, password resets, and the org backend v2 tables (orgs, memberships, invites, seats, subscriptions, policies, reports, audit, budgets).
Ontvangt: Account email + password hash; org membership rows keyed by email; hashed seat/actor identifiers; invite tokens (hashed, never plaintext).
bron:
lib/convex.ts, convex/schema.tsStripe, Inc.
Payment processing and subscription billing. Hosted checkout; card data never reaches our servers.
Ontvangt: Email, name, billing address, plan/price selection. Card details go directly to Stripe.
bron:
lib/stripe.ts, docs/PAYMENTS.mdOpenRouter, Inc.
Routes AI requests (public audit reasoning, dashboard concierge, and the extension's AI vision-escalation tier) to the underlying model provider.
Ontvangt: The prompt/context for the feature in use. For the extension's vision tier: page URL, page title, and a downscaled screenshot (longest edge capped at 1024px, sent only when the URL is not on the safe-domain list and a heuristic or content signal already fired).
bron:
lib/audit/reasoning-agent.ts, syba-agent-extension/lib/api.js (callOpenRouter), syba-agent-extension/lib/heuristics.js (fitDimensions, shouldEscalateToVision)Anthropic, PBC
Claude models behind the public audit reasoning agent and the dashboard concierge, called via @anthropic-ai/sdk with tool_use (never a raw fetch).
Ontvangt: The audit or concierge conversation context for the request in progress.
bron:
lib/audit/reasoning-agent.tsGoogle LLC
Optional Google sign-in, and Google Web Risk as one provider behind /api/extension/url-reputation.
Ontvangt: OAuth profile (email, name) for sign-in. For Web Risk, when GOOGLE_WEB_RISK_API_KEY is set: the full page URL a signed-in user's extension submitted, never page content. Hash-prefix lookups replace full URLs in plan U5 (not shipped).
bron:
app/api/auth/google/route.ts, lib/auth.ts (googleOAuthEnabled), app/api/extension/url-reputation/route.ts (checkGoogleWebRisk)IPQualityScore LLC (IPQS)
URL reputation provider behind /api/extension/url-reputation, called when IPQS_API_KEY is set.
Ontvangt: The full page URL a signed-in user's extension submitted. Stripping before send is planned (U5), not shipped.
bron:
app/api/extension/url-reputation/route.ts (checkIpqs)AgentMail, Inc.
Transactional email: the password reset link to a customer, and internal alerts to SYBA staff. SYBA sends no onboarding, invite, verification or marketing mail.
Ontvangt: For a password reset, the account email address, first name and a single-use reset link. For a staff alert, what the person submitted on the contact, quote, claim or incident form (name, email address, message and incident details), addressed to SYBA staff.
bron:
lib/transactional-email.ts (sendViaAgentMail), lib/auth.ts (emailResetLink), lib/concierge-notify.ts (attemptNotification)Have I Been Pwned (Troy Hunt)
Breach-exposure lookups for the account email you ask us to check, and (v3, when HIBP_API_KEY is configured) for named-breach detail; falls back to a k-anonymity Pwned Passwords presence check.
Ontvangt: The email address being checked (HIBP v3), or a truncated SHA-1 prefix only (k-anonymity fallback: the full hash and the email never leave this server).
bron:
lib/breach-monitor.tsVirusTotal (Google)
URL reputation read behind /api/extension/url-reputation when VIRUSTOTAL_API_KEY is set. Removal approved (O9); it stops at the next production deploy.
Ontvangt: The full page URL, base64url-encoded in the lookup path (a read of an existing report; the URL is never submitted for scanning).
bron:
app/api/extension/url-reputation/route.ts (checkVirusTotal)urlscan.io
Search of existing scans behind /api/extension/url-reputation when URLSCAN_API_KEY is set. Removal approved (O9); it stops at the next production deploy.
Ontvangt: The page URL as a search query; the URL is never submitted for a new scan.
bron:
app/api/extension/url-reputation/route.ts (checkUrlscan)AbuseIPDB
IP reputation behind /api/extension/url-reputation when ABUSEIPDB_API_KEY is set.
Ontvangt: The IP address the page host resolves to; no URL path.
bron:
app/api/extension/url-reputation/route.ts (checkAbuseIpdb)
Gepland voor de 2.0-release
Geen enkele huidige versie stuurt iets naar deze diensten. Ze staan hier vermeld voordat ze gebruikt worden.
Cloudflare, Inc.
Planned (U6, U8): URL Scanner in unlisted mode and certificate-transparency lookalike-domain intelligence for the reputation tier. No current build calls Cloudflare.
Ontvangt: Planned: a stripped URL or domain, never a customer identity.
bron:
docs/plans/2026-09-14-1330-feat-syba-shield-2-enterprise-plan.md (U8, E42)abuse.ch
Planned (U4, U6): licence-clean community malware and phishing data for the bundled blocklist and the consensus tier.
Ontvangt: Planned: a stripped URL or domain.
bron:
docs/plans/2026-09-14-1330-feat-syba-shield-2-enterprise-plan.md (U4, U6)