Sub-processor List

Annex 2 to the Data Processing Agreement · Version 1.0 · Last updated: 24 July 2026

On this page

  1. 1. Sub-processors
  2. 2. Third-party data sources (not sub-processors)
  3. 3. Change notification

  SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.

This Annex 2 lists the sub-processors engaged by SimpleSecurity to process personal data on behalf of the Customer, referenced from the Data Processing Agreement, Section 6.

1. Sub-processors that process personal data

Provider Purpose Personal data Location Safeguard
Amazon Web Services EMEA SARL (AWS) Hosting & infrastructure — compute, storage, authentication and delivery of the Service All customer data processed via the Service Stockholm, Sweden (eu-north-1) AWS Data Processing Addendum (AWS DPA)
Stripe Payments Europe, Ltd. Subscription billing & payment processing Name, email address, billing status EU (Stripe is an independent controller for card data) PCI-DSS certified; Stripe acts as an independent controller for card payment data
Amazon Web Services (AWS SES) Transactional email delivery Recipient email addresses Stockholm, Sweden (eu-north-1) AWS Data Processing Addendum (AWS DPA)

2. Third-party data sources (not sub-processors)

The following third parties are outbound threat-intelligence data sources that SimpleSecurity's vulnerability-scanning feature reads from. They are not sub-processors: SimpleSecurity does not send them customer personal data (with the narrow DNS-over-HTTPS exception noted below), and they do not process personal data on SimpleSecurity's behalf.

Source Purpose Data exchanged
GitHub CVE feed (CVEProject/cvelistV5) CVE vulnerability intelligence Outbound read only — no customer data sent
FIRST.org EPSS Exploit Prediction Scoring System data Outbound read only — no customer data sent
CISA Known Exploited Vulnerabilities (KEV) catalog Known-exploited vulnerability intelligence Outbound read only — no customer data sent
Google & Cloudflare DNS-over-HTTPS (DoH) DNS resolution as part of a customer-configured scan Only the customer's own configured scan domain names — necessary to perform the scan the customer requested; no other personal data is sent

SimpleSecurity does not use advertising networks or third-party analytics/tracking of any kind.

3. Change notification

SimpleSecurity will give at least 30 days' advance notice before adding a new sub-processor or replacing an existing one, via an update to this page and by email to organisation administrators. The Customer may object to a new or replacement sub-processor on reasonable data-protection grounds, in accordance with the Data Processing Agreement, Section 6.

  Trust Center Privacy Notice Terms of Service