Sub-processor List
SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.
This Annex 2 lists the sub-processors engaged by SimpleSecurity to process personal data on behalf of the Customer, referenced from the Data Processing Agreement, Section 6.
1. Sub-processors that process personal data
| Provider | Purpose | Personal data | Location | Safeguard |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS) | Hosting & infrastructure — compute, storage, authentication and delivery of the Service | All customer data processed via the Service | Stockholm, Sweden (eu-north-1) | AWS Data Processing Addendum (AWS DPA) |
| Stripe Payments Europe, Ltd. | Subscription billing & payment processing | Name, email address, billing status | EU (Stripe is an independent controller for card data) | PCI-DSS certified; Stripe acts as an independent controller for card payment data |
| Amazon Web Services (AWS SES) | Transactional email delivery | Recipient email addresses | Stockholm, Sweden (eu-north-1) | AWS Data Processing Addendum (AWS DPA) |
| OVHcloud (OVH Groupe SAS) | Email infrastructure — support mailbox hosting and mail routing | Sender email addresses and message content of support correspondence | EU (France / EU data centres) | OVHcloud Data Processing Agreement (GDPR Art. 28) |
| AWS Bedrock (Amazon Web Services EMEA SARL) | AI-assisted support processing (case triage & drafting assistance, Knowledge-Base answer assistant) | Support-case text and metadata; personal identifiers masked with tokens before processing | EU (Stockholm, eu-north-1); EU-region inference enforced | AWS Data Processing Addendum, personal-data masking before processing, no model-side data retention, human review of all outbound replies |
| Cloudflare, Inc. | DNS hosting for simplesecurity.se, and an inbound-email routing Worker that receives customer replies sent to support@simplesecurity.se and forwards the parsed message to SimpleSecurity's support system | Sender email address and the text content of customer support-reply emails | Global anycast edge network — Cloudflare does not operate from a single fixed data centre; data processed or transferred outside the EEA is governed by Cloudflare's Data Processing Addendum and its incorporated Standard Contractual Clauses | Cloudflare Data Processing Addendum (GDPR Art. 28) and Standard Contractual Clauses; message forwarding to the Worker's API is HMAC-signed over HTTPS |
2. Third-party data sources (not sub-processors)
The following third parties are outbound threat-intelligence data sources that SimpleSecurity's vulnerability-scanning feature reads from. They are not sub-processors: SimpleSecurity does not send them customer personal data (with the narrow DNS-over-HTTPS exception noted below), and they do not process personal data on SimpleSecurity's behalf.
| Source | Purpose | Data exchanged |
|---|---|---|
| GitHub CVE feed (CVEProject/cvelistV5) | CVE vulnerability intelligence | Outbound read only — no customer data sent |
| FIRST.org EPSS | Exploit Prediction Scoring System data | Outbound read only — no customer data sent |
| CISA Known Exploited Vulnerabilities (KEV) catalog | Known-exploited vulnerability intelligence | Outbound read only — no customer data sent |
| EU DNS-over-HTTPS resolvers — DNS.SB (Germany), LibreDNS (Greece), Freifunk München (Germany) | DNS resolution as part of a customer-configured scan | Only the customer's own configured scan domain names — necessary to perform the scan the customer requested; no other personal data is sent. All resolvers are located in the EU; there is no non-EU fallback — if the EU resolvers are unavailable, the check reports "could not be checked" rather than resolving elsewhere |
SimpleSecurity does not use advertising networks or third-party analytics/tracking of any kind.
3. Change notification
SimpleSecurity will give at least 30 days' advance notice before adding a new sub-processor or replacing an existing one, via an update to this page and by email to organisation administrators. The Customer may object to a new or replacement sub-processor on reasonable data-protection grounds, in accordance with the Data Processing Agreement, Section 6.