Aktum beta

aktum / legal / subprocessors

The third parties that process customer data for Aktum

This list is drawn, as of September 2026, from the deployment configuration in the repository, and from nothing else. A subprocessor here is a third party that stores, carries or serves customer data on Aktum’s behalf when your organization uses app.aktum.io. Three things are not subprocessors and are listed further down so the line is clear: your model provider, your GitHub organization, and the sidecar host you run.

Draft for legal review.

The list

Provider What it processes for Aktum Location, as the repository states it
Scaleway object storage Blob bodies of indexed repository text, files uploaded to a room, organization logos and member avatars. Bucket aktum-beta at s3.nl-ams.scw.cloud. nl-ams
Scaleway transactional email Account mail (sign-in, invitation, address confirmation, second-factor reset) and notification mail (a routed question, a mention, a signoff asked of you, an approval gone stale, a decision reverted, a run’s outcome, a hold, a signing-key change), sent from [email protected]. The address it is sent to and the text of the mail pass through the provider. Not recorded in the repository.
The Kubernetes platform operated by Monadial (monadial-cloud) Hosts the studio, the backend and the marketing site as tenant aktum-beta. The database runs on the platform’s shared Postgres cluster and holds what Privacy and data handling lists. Database backups and retention are inherited from the platform and are not documented here. Not recorded in the repository.
Cloudflare Terminates TLS at the tunnel in front of app.aktum.io, aktum.io and www.aktum.io, so every request to app.aktum.io, from a browser or from a sidecar, passes through it. The DNS records for those hostnames are created there. Not recorded in the repository.
Slack For organizations that connect a Slack workspace, and only those: the notification’s text is delivered as a direct message to the member it is for, never to a channel. Aktum holds the workspace’s access token and, per member, the Slack user id matched to an email address verified on their Aktum account. When a member answers from inside Slack, Slack sends that action to Aktum. Disconnecting removes the token and stops delivery. Not recorded in the repository. Slack is operated from the United States; the transfer rests on the standard contractual clauses.
GitHub For organizations that connect a repository: the GitHub App you installed and can revoke, its webhooks, and the installation tokens minted through it. The backend reads repository content and opens the consent pull request through the GitHub App you installed and can revoke. Not recorded in the repository. The connection is to github.com; no other git host is supported.

Every row above is read from the chart and the build workflows in the repository. [code audit · September 2026]

Not a subprocessor here

Your model provider. Aktum operates no model. Model traffic goes from the workers behind the sidecar you run to the endpoint you configure, under your keys: Anthropic, OpenAI, or any OpenAI-compatible endpoint, with Ollama as the local default. What that provider keeps is governed by your contract with it, and it appears on no list of Aktum’s.

Your GitHub organization. GitHub is on the list above because the App acts through GitHub’s systems. Your organization’s repositories, members and settings stay yours; Aktum reaches them only through the App you installed, and uninstalling it on GitHub ends that access.

The sidecar host you run. The sidecar runs on a machine you control and is operated by you. Nothing of it deploys to Aktum’s platform. A machine of yours is not a third party.

Named in the repository, not on the list

The container registry. The images the platform runs are pushed to a Scaleway container registry at rg.nl-ams.scw.cloud and pulled from there. It holds Aktum’s own images and no customer data. The hostname carries the region code nl-ams.

Tracing inside the cluster. The backend exports traces to the platform’s own trace store inside the cluster, named in the chart, and to no third party.

Slack. On the list above, and only for an organization that has connected it. Until an organization admin connects a Slack workspace, nothing is sent and no token is held.

Changes to this list

This page carries dated versions. A provider added, removed, or changed in purpose or location appears as a new version with its date; the earlier versions stay readable.

draft · 6 September 2026

Contact

A question about this list is read by a person and answered by email.

Draft for legal review.