This inventory records the providers and processing paths verified in the current SecurityOla deployment records. Unknown provider identity, location or transfer terms are marked instead of guessed.
Paddle
Purpose: merchant-of-record checkout, billing and transaction webhooks.
Data: payment and billing information, contact details, customer/transaction/subscription references.
Location/transfers: not fixed in the verified SecurityOla deployment records; Paddle contract and current privacy/subprocessor terms require review.
Amazon SES SMTP
Purpose: server-side report, support and operational email delivery.
Data: recipient address/name, subject/body selected by the service, delivery result and provider message reference.
Evidence: API source uses an SES SMTP driver; the configured host and mailbox are intentionally not published here.
Location/transfers: provider contract and current region require verification.
SecurityOla VPS and local stores
Purpose: API execution, entitlement/site/release state, bounded logs, monitoring and support diagnostics.
Data: account and license identifiers, site metadata, findings/status metadata, operational logs and security evidence.
Location: the current server is 172.93.167.134; the hosting provider’s legal identity and geographic processing location are not recorded in the verified materials.
Backblaze B2 AppCare adapter
Purpose: separately scoped AppCare BETA-04 off-site backup handoff and readback.
Data: backup artifacts and manifests for that isolated AppCare scope.
Evidence: the server has a fixed B2 S3-compatible endpoint in the us-east-005 region and a 24-hour BETA-04 operational setting. This is not represented as a universal SecurityOla self-service retention promise.
Monitoring and error reporting
Purpose: the SecurityOla monitor runs from a server cron job and writes bounded local monitor/alert logs. No separate external error-reporting provider was observed in the current API/site paths.
AI/model providers
No AI/model provider receiving SecurityOla customer files, database contents or scan evidence was observed in the current production API or canonical site paths. No such transfer is authorized by this inventory.
The legal hosting entity, provider contract identities, processing locations, transfer mechanisms, retention schedule and any future provider additions must be verified and recorded before this inventory is treated as complete. If scanned customer files or databases are ever sent to an AI provider, that change requires owner review and a new inventory entry first.