Sub-processor List

Annex 2 to the Data Processing Agreement · Version 1.2 · Last updated: 2 September 2026

On this page

  1. 1. Sub-processors
  2. 2. Third-party data sources (not sub-processors)
  3. 3. Change notification

  SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.

This Annex 2 lists the sub-processors engaged by SimpleSecurity to process personal data on behalf of the Customer, referenced from the Data Processing Agreement, Section 6.

1. Sub-processors that process personal data

Provider Purpose Personal data Location Safeguard
Amazon Web Services EMEA SARL (AWS) Hosting & infrastructure — compute, storage, authentication and delivery of the Service All customer data processed via the Service Stockholm, Sweden (eu-north-1) AWS Data Processing Addendum (AWS DPA)
Stripe Payments Europe, Ltd. Subscription billing & payment processing Name, email address, billing status EU (Stripe is an independent controller for card data) PCI-DSS certified; Stripe acts as an independent controller for card payment data
Amazon Web Services (AWS SES) Transactional email delivery Recipient email addresses Stockholm, Sweden (eu-north-1) AWS Data Processing Addendum (AWS DPA)
OVHcloud (OVH Groupe SAS) Email infrastructure — support mailbox hosting and mail routing Sender email addresses and message content of support correspondence EU (France / EU data centres) OVHcloud Data Processing Agreement (GDPR Art. 28)
AWS Bedrock (Amazon Web Services EMEA SARL) AI-assisted support processing (case triage & drafting assistance, Knowledge-Base answer assistant) Support-case text and metadata; personal identifiers masked with tokens before processing EU (Stockholm, eu-north-1); EU-region inference enforced AWS Data Processing Addendum, personal-data masking before processing, no model-side data retention, human review of all outbound replies
Cloudflare, Inc. DNS hosting for simplesecurity.se, and an inbound-email routing Worker that receives customer replies sent to support@simplesecurity.se and forwards the parsed message to SimpleSecurity's support system Sender email address and the text content of customer support-reply emails Global anycast edge network — Cloudflare does not operate from a single fixed data centre; data processed or transferred outside the EEA is governed by Cloudflare's Data Processing Addendum and its incorporated Standard Contractual Clauses Cloudflare Data Processing Addendum (GDPR Art. 28) and Standard Contractual Clauses; message forwarding to the Worker's API is HMAC-signed over HTTPS

2. Third-party data sources (not sub-processors)

The following third parties are outbound threat-intelligence data sources that SimpleSecurity's vulnerability-scanning feature reads from. They are not sub-processors: SimpleSecurity does not send them customer personal data (with the narrow DNS-over-HTTPS exception noted below), and they do not process personal data on SimpleSecurity's behalf.

Source Purpose Data exchanged
GitHub CVE feed (CVEProject/cvelistV5) CVE vulnerability intelligence Outbound read only — no customer data sent
FIRST.org EPSS Exploit Prediction Scoring System data Outbound read only — no customer data sent
CISA Known Exploited Vulnerabilities (KEV) catalog Known-exploited vulnerability intelligence Outbound read only — no customer data sent
EU DNS-over-HTTPS resolvers — DNS.SB (Germany), LibreDNS (Greece), Freifunk München (Germany) DNS resolution as part of a customer-configured scan Only the customer's own configured scan domain names — necessary to perform the scan the customer requested; no other personal data is sent. All resolvers are located in the EU; there is no non-EU fallback — if the EU resolvers are unavailable, the check reports "could not be checked" rather than resolving elsewhere

SimpleSecurity does not use advertising networks or third-party analytics/tracking of any kind.

3. Change notification

SimpleSecurity will give at least 30 days' advance notice before adding a new sub-processor or replacing an existing one, via an update to this page and by email to organisation administrators. The Customer may object to a new or replacement sub-processor on reasonable data-protection grounds, in accordance with the Data Processing Agreement, Section 6.

  Trust Center Privacy Notice Terms of Service