Subprocessors.
We run our own hardware. The subprocessor list is short because almost nothing leaves infrastructure we own and operate — this page is the canonical, versioned inventory.
01 · Operating model
SecurityVault runs on bare-metal infrastructure that we own and operate. Compute, databases, object storage, analytics, observability, secrets management, CI, container registry, and AI inference are all first-party, in-house systems. The only third parties that touch any data are at the network edge. This page is the canonical subprocessor inventory referenced by our DPA and privacy notice.
02 · Subprocessor list
| Subprocessor | Purpose | Personal data touched | Region |
|---|---|---|---|
| Cloudflare, Inc. | DNS, TLS termination, DDoS protection and WAF for our public hostnames | Visitor IP addresses and request metadata, in transit only | Global edge |
Supporting services that process no personal data: Let's Encrypt (ISRG) issues our TLS certificates via ACME and sees only public hostnames.
03 · First-party stack
For transparency — the platform functions that other vendors typically outsource, and where they run here:
- Compute & orchestration — Kubernetes on hardware we operate; per-scan workloads run in isolated, ephemeral namespaces.
- Data stores — PostgreSQL, Redis, ClickHouse (analytics), and MinIO (object storage), all in-cluster and encrypted at rest.
- Observability — Prometheus, Loki, and Grafana, self-hosted. No telemetry SaaS receives operational logs.
- Secrets — HashiCorp Vault, self-hosted; encryption master keys never leave it.
- AI inference — language models are hosted inside the same infrastructure as your tenant. Customer content is never sent to a third-party AI provider, and models are never trained on customer data.
- Email — transactional mail is sent over TLS-verified SMTP from infrastructure we control.
- CI & registry — GitLab, Jenkins, and Harbor, all self-hosted.
04 · What we do not use
No hyperscaler holds tenant data. No third-party analytics warehouse, no external observability SaaS, no CRM pixel on the product, no external AI API on customer content, no email-marketing platform with access to product data. If a category is absent from the table in section 02, it is not a gap in the list — it is a deliberate absence in the architecture.
05 · Change notification
Material changes to this list are announced at least 30 days in advance to customer security contacts and recorded on the changelog. Customers may object on reasonable data-protection grounds under the DPA; if we cannot resolve an objection, the affected service can be terminated with a pro-rata refund. Every subprocessor operates under a written data-processing agreement equivalent to our customer DPA, reviewed annually.