Subprocessor List
SecurityPassport
Last updated: June 3, 2026
1. Purpose
This Subprocessor List describes third-party providers that may support the operation, security, delivery, billing, monitoring, or communication workflows of SecurityPassport.
SecurityPassport uses subprocessors only where necessary to provide the platform, support customer workspaces, maintain service reliability, process payments, deliver communications, operate infrastructure, or protect the service.
2. Scope
Subprocessors may process limited customer data, account data, operational metadata, security logs, billing data, or service communication data depending on the service they provide.
SecurityPassport remains responsible for its subprocessors under applicable agreements and data protection obligations.
3. Subprocessor Categories
| Category | Purpose | Data Processed |
|---|---|---|
| Cloud infrastructure | Hosting application, databases, runtime services, and production workloads | Customer workspace data, operational metadata, account data |
| Object storage | Storing uploaded evidence, exports, attachments, and generated files | Customer-controlled files and metadata |
| Email delivery | Sending authentication, notification, support, and service emails | Email address, message metadata, service messages |
| Payment processing | Processing subscriptions, invoices, and billing events | Billing contact data, payment metadata |
| Monitoring and logging | Reliability, security monitoring, diagnostics, and incident investigation | Operational logs, request metadata, error data |
| Authentication and identity | Login, session, and identity-related workflows | Account identifiers, authentication metadata |
4. Security and Contractual Controls
SecurityPassport evaluates subprocessors based on the role they perform, the data they process, and the security or operational risk they introduce.
Subprocessors are expected to maintain appropriate technical and organizational controls, confidentiality obligations, access restrictions, and data protection commitments.
5. International Transfers
Where subprocessors process personal data outside the European Economic Area, SecurityPassport relies on appropriate transfer safeguards such as Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms where applicable.
6. Updates
SecurityPassport may update this list when subprocessors are added, removed, or materially changed.
Customers with contractual notification rights may receive notice according to their agreement.
7. Contact
Questions about subprocessors may be sent to:
SecurityPassport
Rue Elisabeth
5030 Gembloux
Belgium
Email: hello@securitypassport.com