Skip to main content

Vertrouwenscentrum

Wie gegevens voor ons verwerkt.

12 diensten vandaag in gebruik. Elke rij vermeldt wat de dienst ontvangt en welke code het verstuurt, zodat u het kunt controleren.

  • Netlify, Inc.

    hosting, US (Netlify global edge; primary compute region us-east).

    Hosts this site and its serverless functions; Netlify Blobs is the primary key-value store for accounts, subscriptions, seat-report ledgers, audits, policies and vault documents.

    Ontvangt: Everything the app persists outside Convex. The store-by-store inventory is in lib/data-stores.ts.

    bron: lib/blobs.ts, netlify.toml

  • Convex, Inc.

    database, US (Convex deployment wooden-crow-226).

    System of record for user accounts, password resets, and the org backend v2 tables (orgs, memberships, invites, seats, subscriptions, policies, reports, audit, budgets).

    Ontvangt: Account email + password hash; org membership rows keyed by email; hashed seat/actor identifiers; invite tokens (hashed, never plaintext).

    bron: lib/convex.ts, convex/schema.ts

  • Stripe, Inc.

    payments, US, with EU processing for the Syba Europe BV account.

    Payment processing and subscription billing. Hosted checkout; card data never reaches our servers.

    Ontvangt: Email, name, billing address, plan/price selection. Card details go directly to Stripe.

    bron: lib/stripe.ts, docs/PAYMENTS.md

  • OpenRouter, Inc.

    ai-inference, US-based routing; underlying model region depends on the provider selected.

    Routes AI requests (public audit reasoning, dashboard concierge, and the extension's AI vision-escalation tier) to the underlying model provider.

    Ontvangt: The prompt/context for the feature in use. For the extension's vision tier: page URL, page title, and a downscaled screenshot (longest edge capped at 1024px, sent only when the URL is not on the safe-domain list and a heuristic or content signal already fired).

    bron: lib/audit/reasoning-agent.ts, syba-agent-extension/lib/api.js (callOpenRouter), syba-agent-extension/lib/heuristics.js (fitDimensions, shouldEscalateToVision)

  • Anthropic, PBC

    ai-inference, US.

    Claude models behind the public audit reasoning agent and the dashboard concierge, called via @anthropic-ai/sdk with tool_use (never a raw fetch).

    Ontvangt: The audit or concierge conversation context for the request in progress.

    bron: lib/audit/reasoning-agent.ts

  • Google LLC

    identity, Global (Google infrastructure).

    Optional Google sign-in, and Google Web Risk as one provider behind /api/extension/url-reputation.

    Ontvangt: OAuth profile (email, name) for sign-in. For Web Risk, when GOOGLE_WEB_RISK_API_KEY is set: the full page URL a signed-in user's extension submitted, never page content. Hash-prefix lookups replace full URLs in plan U5 (not shipped).

    bron: app/api/auth/google/route.ts, lib/auth.ts (googleOAuthEnabled), app/api/extension/url-reputation/route.ts (checkGoogleWebRisk)

  • IPQualityScore LLC (IPQS)

    threat-intel, US.

    URL reputation provider behind /api/extension/url-reputation, called when IPQS_API_KEY is set.

    Ontvangt: The full page URL a signed-in user's extension submitted. Stripping before send is planned (U5), not shipped.

    bron: app/api/extension/url-reputation/route.ts (checkIpqs)

  • AgentMail, Inc.

    email, United States (AgentMail, Inc., San Francisco; its privacy policy states data is transferred to and processed in the US).

    Transactional email: the password reset link to a customer, and internal alerts to SYBA staff. SYBA sends no onboarding, invite, verification or marketing mail.

    Ontvangt: For a password reset, the account email address, first name and a single-use reset link. For a staff alert, what the person submitted on the contact, quote, claim or incident form (name, email address, message and incident details), addressed to SYBA staff.

    bron: lib/transactional-email.ts (sendViaAgentMail), lib/auth.ts (emailResetLink), lib/concierge-notify.ts (attemptNotification)

  • Have I Been Pwned (Troy Hunt)

    threat-intel, Global (Cloudflare-fronted).

    Breach-exposure lookups for the account email you ask us to check, and (v3, when HIBP_API_KEY is configured) for named-breach detail; falls back to a k-anonymity Pwned Passwords presence check.

    Ontvangt: The email address being checked (HIBP v3), or a truncated SHA-1 prefix only (k-anonymity fallback: the full hash and the email never leave this server).

    bron: lib/breach-monitor.ts

  • VirusTotal (Google)

    threat-intel, Not established from our code; see the provider's terms.

    URL reputation read behind /api/extension/url-reputation when VIRUSTOTAL_API_KEY is set. Removal approved (O9); it stops at the next production deploy.

    Ontvangt: The full page URL, base64url-encoded in the lookup path (a read of an existing report; the URL is never submitted for scanning).

    bron: app/api/extension/url-reputation/route.ts (checkVirusTotal)

  • urlscan.io

    threat-intel, Not established from our code; see the provider's terms.

    Search of existing scans behind /api/extension/url-reputation when URLSCAN_API_KEY is set. Removal approved (O9); it stops at the next production deploy.

    Ontvangt: The page URL as a search query; the URL is never submitted for a new scan.

    bron: app/api/extension/url-reputation/route.ts (checkUrlscan)

  • AbuseIPDB

    threat-intel, Not established from our code; see the provider's terms.

    IP reputation behind /api/extension/url-reputation when ABUSEIPDB_API_KEY is set.

    Ontvangt: The IP address the page host resolves to; no URL path.

    bron: app/api/extension/url-reputation/route.ts (checkAbuseIpdb)

Gepland voor de 2.0-release

Geen enkele huidige versie stuurt iets naar deze diensten. Ze staan hier vermeld voordat ze gebruikt worden.

  • Cloudflare, Inc.

    threat-intel, Global (Cloudflare network).

    Planned (U6, U8): URL Scanner in unlisted mode and certificate-transparency lookalike-domain intelligence for the reputation tier. No current build calls Cloudflare.

    Ontvangt: Planned: a stripped URL or domain, never a customer identity.

    bron: docs/plans/2026-09-14-1330-feat-syba-shield-2-enterprise-plan.md (U8, E42)

  • abuse.ch

    threat-intel, Switzerland (Bern University of Applied Sciences).

    Planned (U4, U6): licence-clean community malware and phishing data for the bundled blocklist and the consensus tier.

    Ontvangt: Planned: a stripped URL or domain.

    bron: docs/plans/2026-09-14-1330-feat-syba-shield-2-enterprise-plan.md (U4, U6)