Skip to main content

Security

Subprocessors and connected services

Third-party services and the limits on what Nebula has verified.

How to read this register

This register names third-party services that may receive customer or public-site visitor data through Nebula. It includes Nebula-appointed, browser-direct and customer-directed paths without deciding their legal classification. Provider-published information does not prove that Nebula has accepted those terms, selected an available region or activated a service. This register does not replace legal review, approve a supplier or prove an account's selected region. A path shown as not verified or not yet approved is not an approved supplier path.

Public-source verification

Provider-owned public documents were reviewed on 01/08/2026. Confirmed applies only to the cited public information. Corrected marks a material correction to the previous review. Account settings and service approvals remain unverified where stated.

ProviderReview positionProvider-published public-source positionOfficial sources
RailwayProduction hosting verified. Processing locations and contractual settings not verified.Railway Corporation publishes its terms and privacy policy. Nebula's production service and live public site were confirmed on Railway on 7 September 2026. The application region and log, support, control-plane and backup locations have not been verified.
NeonCorrected public information. Account configuration not verified.The current public terms stack is a Neon, LLC product schedule under the Databricks, Inc. MCSA and DPA. AWS Sydney is a project option, not proof of Nebula's project region.
Cloudflare R2Corrected public information. Account configuration not verified.Cloudflare, Inc. publishes the standard terms and DPA. region: auto is an unused S3 compatibility value, not a bucket location. APAC and Oceania hints are best effort only.
ResendCorrected public information. Account configuration not verified.Plus Five Five, Inc. publishes the terms and DPA. Sending region does not change United States storage for account data, email metadata, logs and API records. Standard email-data retention is 30 days.
Google Analytics 4 and linked Google AdsCorrected public information. Account configuration not verified.Standard Analytics terms identify Google LLC; Australia Ads terms identify Google Australia Pty Ltd. The products have different public role terms and global processing. Reporting timezone is not a data region.
Google Calendar appointment schedulingPublic information reviewed. Account type not yet confirmed.The entity and region rule depends on whether the schedule is a general Google Account or Workspace service. Eligible Workspace editions offer United States or Europe data regions for listed Calendar data, not Australia.
AnthropicCorrected public information. Account configuration not verified.Anthropic, PBC is the published Australian commercial counterparty. Public terms prohibit training on Customer Content subject to stated opt-ins and feedback exceptions. Data is stored in the United States; inference geography can be global or United States. Nebula's current model configuration includes Claude Fable 5, which Anthropic classifies as requiring 30-day retention and excluding zero data retention.
MET Norway LocationforecastConfirmed public information. Server-proxied path; current deployment use not verified.The Norwegian Meteorological Institute publishes Locationforecast as open data under NLOD 2.0 and CC BY 4.0. Its official licensing page says that its data is free to use, including the commercial use permitted by those licences. Requests must identify Nebula, respect provider cache headers and credit MET Norway. MET stores API access logs in its Oslo data centre and says IP addresses for unauthenticated websites can be held for up to 90 days. Nebula's server proxy sends rounded coordinates and Nebula service request details, not a visitor IP address or account identifier. MET offers no delivery guarantee or SLA.
Fly.ioCorrected public information. Account configuration not verified.Fly.io, Inc. publishes the service terms and offers a Sydney Machine region. Its terms allow Customer Data use to provide and improve services, while its Privacy Statement describes information it collects as United States stored and processed. A Sydney capability does not prove the staging-named gateway's Machine, Volume, log, support or backup boundary. Fly says its DPA requires customer signature.
StripeCorrected public information. Account configuration not verified.For Australian Account Country, public terms name Stripe Payments Australia Pty Ltd and add Stripe Payments Europe, Limited only for section 4 of the service agreement; the DPA separately names Stripe Payments Europe, Limited. Stripe discloses United States and global transfers. No Australia-only processing or data-residency commitment was identified in the cited public sources as at 01/08/2026.

Provider services

ProviderEvidence statusPurposeData categoriesLocation position
RailwayProduction application hosting confirmed on 7 September 2026 against the Railway service and the live public site.Application hosting and scheduled work. The containerised application includes embedded schedules.Requests and responses, account and session context, server-processed application payloads, source documents and extracted text handled by workers, generated files, service metadata and platform logs.The deployed region, static delivery, control-plane, support, telemetry and log-processing locations are not established. No region is claimed until it is verified against the account.
NeonConfiguration was verified on 16/05/2026 and has not been rechecked.Managed PostgreSQL for structured operational records.Account, organisation, engagement, audit, integration, billing and operational records.The application uses managed PostgreSQL. The production project region is not established by available configuration or signed provider terms.
CloudflareConfiguration was verified on 16/05/2026 and has not been rechecked.R2 object storage for documents and files.Source documents, evidence files, generated files and application-managed object metadata.The S3 client uses Cloudflare's required compatibility value region: auto. That value is not a bucket location selection. The production bucket placement or jurisdiction is not established by code.
ResendOne fresh production signup verification message was recorded as sent and delivered by Resend and reached Gmail Inbox on 26/07/2026. The sending domain, DKIM and SPF were verified and no suppressions were shown. The link was not clicked. Continuing delivery health and post-verification account state remain unverified.Transactional email, support and contact-message delivery.Recipient and sender details, internal user identifier, complete message content, account links, support and contact content, engagement details, operational notices, payment summaries and delivery metadata.Public documents state that account data, email metadata, logs and API records are stored in the United States regardless of sending region. Nebula's domain sending region and any plan override are not established.
Google Analytics 4 and linked Google AdsGoogle Analytics operates on the public site after consent, with one page view verified on 26/07/2026. The application keeps only the five disclosed UTM campaign fields on static marketing page locations and maps record-specific values in the manual call's page-path, page-location and same-origin page-referrer fields. A browser test confirms the contact form queues one lead event after consent and none after refusal. Provider ingestion, deployment after the fix and the complete provider-generated event boundary have not been verified from a production request or Analytics account export. The Google Ads product link is completed. An account review dated 26/07/2026 records lead_submitted as the primary Submit lead form conversion with status Awaiting conversions, property-level ads personalisation allowed in 0 of 307 regions, and Google signals off.Public website usage and consent-gated conversion measurement, with a configured Google Ads relationship for advertising conversion measurement. Analytics data is disallowed for personalised advertising at the property level. Signup event calls exist outside the tagged public surface and their delivery is not established. The Search campaign was published and immediately paused. A subsequent account check showed it Paused with its A$50.00 average daily budget unchanged, and the immediate overview showed zero impressions, clicks, conversions and cost before the pause. Future campaign delivery and spend remain unverified.The manual page-view call sends a static route or route class in the page-path field, the origin and that same path in the page-location field, and a reduced same-origin referrer or unchanged external referrer in the page-referrer field. On static marketing pages only, page-location can also carry utm_source, utm_medium, utm_campaign, utm_term and utm_content; other query values are removed. Google also receives ordinary browser request metadata and can add fields. Implemented event values include lead form type, enquiry category, signup context and requested plan, and a founding workspace-presence flag, remaining-place count and programme duration. The application mapping excludes record-specific tokens, organisation identifiers, anchor identifiers, ABNs and block heights from the page-path and page-location fields, and from the page-referrer field when the referrer is within Nebula. The primary conversion is the lead_submitted GA event, whose implemented parameters are form type and enquiry category. A browser test confirms dispatch after consent, but provider ingestion is unverified. Separate funnel-event parameters do not explicitly include names, email addresses, free-text messages, passwords, documents, organisation names, account identifiers or engagement content. Complete fields added by Google, provider-generated page views and the exact data made available through the link or conversion are not established. The application leaves advertising storage, advertising user data and advertising personalisation denied when analytics storage is granted. Property-level ads personalisation is allowed in 0 of 307 regions and Google signals is off, but the complete linked-service data boundary is not established.Google documents global collection and processing. The reporting country, property timezone and Ads billing settings are not processing regions. Public terms identify Google LLC for standard Analytics and Google Australia Pty Ltd for Australia-based Ads customers. Accepted versions, Analytics retention and linked-service roles remain unverified.
Google Calendar appointment schedulingA public schedule was observed on 27/07/2026, and Nebula's Business and Enterprise pricing actions link to it. No completed attendee booking or deployed pricing-path check has been verified.Owner-operated, Google-hosted public appointment scheduling linked from Nebula for Business and Enterprise introduction requests. This is separate from customer-selected Google identity and Google Workspace integrations.A visitor's browser supplies the client IP address and ordinary request metadata when the external page is opened. The Google-hosted appointment page collects attendee name, email address and selected appointment time. The observed schedule was configured for calendar invitations and updates by email and Google Meet generation, but no completed booking, resulting email, calendar event or Meet link was observed end to end.The Australia/Brisbane display setting is not a processing region. Public terms identify Google LLC for a general Google Account or Google Australia Pty Ltd under the qualified Workspace rule. Eligible Workspace editions offer United States or Europe data regions for listed Calendar data. Account type, agreement, controls, legal role, retention and deletion remain open.
AnthropicConfiguration was verified on 16/05/2026 and has not been rechecked.Document intelligence through Nebula's sanctioned AI boundary.System instructions, extracted document text, file names, engagement context, model output and complete PDFs for native document calls.Public terms identify Anthropic, PBC for Australian commercial customers, United States storage and global or United States inference geography. Nebula's current model configuration includes Claude Fable 5, which Anthropic classifies as requiring 30-day retention and excluding zero data retention. Nebula does not send an inference geography, but a workspace default may apply. Accepted terms and account settings remain unverified.
MET Norway LocationforecastNebula's source uses a cached server proxy. Current production use and legal classification are not verified.Current weather for the authenticated dashboard after Nebula resolves a saved, entered or timezone-derived city inside its own service. The browser contacts only Nebula.Coordinates rounded to no more than four decimals, Nebula's server IP, a stable Nebula service identity and ordinary server request details. The visitor's IP address, cookies, session data, account or organisation identifiers, and city text remain within Nebula.MET says api.met.no access logs are stored in its own Oslo data centre. Its Privacy Policy says IP addresses for unauthenticated websites can be stored for up to 90 days. Under the proxy boundary, that is Nebula's server IP rather than the visitor's IP. MET offers no delivery guarantee or SLA.
StripeTest-mode hosted Checkout and server-side reconciliation operated against the production deployment on 26/07/2026. The active production webhook endpoint and 11 event subscriptions were recorded. A signing-secret mismatch was corrected in the production deployment and the redeploy completed. Stripe showed no event deliveries, so live-money mode and end-to-end webhook delivery remain unverified.Hosted subscription checkout, founding payments, Orbits top-ups, billing portal, payment reconciliation, invoices and refunds when configured.Organisation, product, price and checkout-intent identifiers; mode, amount and currency; Orbits, founding and discount metadata; provider-issued customer, checkout, subscription, payment, invoice, charge and refund identifiers; and billing status. A hosted test collected a payer name and payment-card details directly on Stripe's surface. An email address may also be collected there. Production callers do not pass a customer email from Nebula.For Australian Account Country, public terms identify Stripe Payments Australia Pty Ltd, add Stripe Payments Europe, Limited only for section 4 of the service agreement and separately name Stripe Payments Europe, Limited for DPA processing. Stripe discloses United States and global transfers. No Australia-only processing or data-residency commitment was identified in the cited public sources as at 01/08/2026. Accepted terms and account settings remain unverified.

Configuration-dependent providers

ProviderActivation conditionData categoriesEvidence position
Fly.ioUse for the Nebula-operated proof gateway was last verified on 16/05/2026.Signed canonical proof events, internal identifiers, event details, evidence hashes and signatures. Source document files are not included.Public terms identify Fly.io, Inc., allow Customer Data use to provide and improve services and offer a Sydney Machine region. The Privacy Statement describes information it collects as United States stored and processed. The current gateway, deployed Machine and Volume regions, signed DPA, logs, snapshots and staging-named boundary require account evidence.
SentryUsed only when a Sentry DSN is configured.Application error, request and diagnostic context selected by the configured telemetry path.Sentry was not configured when last checked on 16/05/2026.
UpstashUsed only when shared Redis-backed rate limiting is configured.Rate-limit keys and counters. A key can include the caller identifier supplied by the protected route, including an IP address, user identifier or organisation identifier.The application otherwise uses an in-process rate-limit store.
Alchemy or another selected Polygon JSON-RPC providerUsed only when public Polygon proof submission is configured.Proof commitments and transaction metadata. Source documents are not submitted.Nebula defaults to an Alchemy Polygon Amoy demo endpoint when no Polygon RPC URL is supplied. The selected production provider is not identified by available configuration.

AI provider boundary

Nebula's model registry is provider-neutral and multi-model. This register lists Anthropic because it is the most recently verified AI provider configuration for customer data. A customer-specific deployment must confirm the provider and model available before use.

Customer-directed and user-initiated services

Customer-selected identity and connected services, including Microsoft Entra ID, Microsoft 365, Google identity, Google Workspace, authorised business-system integrations and external webhooks, are assessed for the customer deployment. Polygonscan is opened only when a user follows a public transaction link. A service may be the customer's own provider, an independent controller, an external destination or a Nebula subprocessor depending on the contractual arrangement.

ServicePurposeData categories
Microsoft Entra ID and Microsoft 365Customer-selected sign-in, directory, SCIM, SharePoint, Outlook and Teams connections.Identity claims, directory records and customer-authorised service metadata or content within granted scopes.
Google identity and Google WorkspaceCustomer-selected sign-in, directory, SCIM, Drive, Gmail, Calendar and Chat connections.Identity claims, directory records and customer-authorised service metadata or content within granted scopes.
XeroCustomer-authorised finance and time-entry integration.Tenant, invoice, payment, project and time-entry data within granted scopes.
QuickBooks OnlineCustomer-authorised finance and time-activity integration.Realm, invoice, payment and time-activity data within granted scopes.
MYOBCustomer-authorised company-file, invoice and timesheet integration.Company, invoice, timesheet and authorised identity data within granted scopes.
ProcoreCustomer-authorised project and construction-system integration.Project, company, document, field, labour, time and cost data within granted access.
Oracle AconexCustomer-authorised project, document and correspondence integration.Project, organisation, document revision and correspondence data within granted access.
Customer-configured webhook endpointOrganisation-selected delivery of subscribed project events to an external HTTPS endpoint.Event type and time, project and record identifiers, status and action details, and event-specific file, payment, dispute, notification or user data.
PolygonscanUser-initiated inspection of a public Polygon transaction in a third-party block explorer.Client IP address, ordinary request metadata and the public transaction hash in the URL. Source documents are not sent by Nebula.

Public proof networks

Polygon submission is configuration-dependent and has not been verified as active. When enabled, Nebula publishes a SHA-256 commitment and transaction metadata rather than the source document. A confirmed public-network record cannot be removed by Nebula.

Changes and questions

Any applicable data processing agreement must set advance notice and objection rights for a new subprocessor. No notice period is established by this register. A dated history of register changes appears below. Privacy and procurement questions can be sent to privacy@nebulaplatform.com.au.

Review Nebula's security and data handling statement for the related control posture.

Evidence updates

01/08/2026
Reviewed provider entities, terms and region statements. This review is limited to the recorded facts and stated unknowns. It does not approve a supplier or turn a public regional capability into account evidence. On the same date, Nebula replaced the two browser-direct dashboard weather paths with a cached server proxy to MET Norway Locationforecast. Current deployment use and legal classification remain unverified.
27/07/2026
Added the Google Calendar appointment path linked from Nebula after its public schedule was observed and the Business and Enterprise pricing actions were confirmed to link to it. A completed attendee booking, signed provider terms, legal classification, processing location, retention position, transfer position and procurement approval remain unverified. The direct path preceded its register entry and booking-specific provider review.
26/07/2026
Added the observed ads privacy controls and paused campaign state, Stripe price mapping and Team Checkout evidence. Production Analytics payload evidence, provider-generated page-view behaviour, Business Checkout, mapping audit rows, payment activation, webhook delivery, conversion ingestion and provider checks remain open.
26/07/2026
Added dated application and production evidence for Analytics, Google Ads, Resend and Stripe, including the prepared setup handoff. Production payload evidence, provider-generated page-view behaviour, continuing email health, Stripe delivery, conversion ingestion and provider checks remain open.
26/07/2026
Documented the deployed route-class mapping for the explicit page-path field and the residual automatically collected page-location and referrer boundary. Complete route control, linked-service evidence and provider checks remain open.
26/07/2026
Reviewed Google Analytics 4, linked Google Ads, the then-current application host, Resend and Stripe against application behaviour and dated production evidence. The analytics route control, linked-service data boundary and provider terms, region, retention and legal-classification checks remain open.
25/07/2026
Published the initial provider register, including browser-direct weather services and customer webhooks.