Sub-processor List
SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.
This Annex 2 lists the sub-processors engaged by SimpleSecurity to process personal data on behalf of the Customer, referenced from the Data Processing Agreement, Section 6.
1. Sub-processors that process personal data
| Provider | Purpose | Personal data | Location | Safeguard |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS) | Hosting & infrastructure — compute, storage, authentication and delivery of the Service | All customer data processed via the Service | Stockholm, Sweden (eu-north-1) | AWS Data Processing Addendum (AWS DPA) |
| Stripe Payments Europe, Ltd. | Subscription billing & payment processing | Name, email address, billing status | EU (Stripe is an independent controller for card data) | PCI-DSS certified; Stripe acts as an independent controller for card payment data |
| Amazon Web Services (AWS SES) | Transactional email delivery | Recipient email addresses | Stockholm, Sweden (eu-north-1) | AWS Data Processing Addendum (AWS DPA) |
2. Third-party data sources (not sub-processors)
The following third parties are outbound threat-intelligence data sources that SimpleSecurity's vulnerability-scanning feature reads from. They are not sub-processors: SimpleSecurity does not send them customer personal data (with the narrow DNS-over-HTTPS exception noted below), and they do not process personal data on SimpleSecurity's behalf.
| Source | Purpose | Data exchanged |
|---|---|---|
| GitHub CVE feed (CVEProject/cvelistV5) | CVE vulnerability intelligence | Outbound read only — no customer data sent |
| FIRST.org EPSS | Exploit Prediction Scoring System data | Outbound read only — no customer data sent |
| CISA Known Exploited Vulnerabilities (KEV) catalog | Known-exploited vulnerability intelligence | Outbound read only — no customer data sent |
| Google & Cloudflare DNS-over-HTTPS (DoH) | DNS resolution as part of a customer-configured scan | Only the customer's own configured scan domain names — necessary to perform the scan the customer requested; no other personal data is sent |
SimpleSecurity does not use advertising networks or third-party analytics/tracking of any kind.
3. Change notification
SimpleSecurity will give at least 30 days' advance notice before adding a new sub-processor or replacing an existing one, via an update to this page and by email to organisation administrators. The Customer may object to a new or replacement sub-processor on reasonable data-protection grounds, in accordance with the Data Processing Agreement, Section 6.