SecQon Sub-processors
Effective date: 28 September 2026 · Version: 2026-09-v4
This page lists every third party that processes personal data when you use SecQon. It is the list that Data Processing Agreement §7 authorises, kept where it can change without re-issuing the DPA. The change log at the bottom records each change.
The list is short, by design. Customer Data is hosted and model inference runs in Google Cloud's asia-south1 (Mumbai) region. Outside Google, two processors can see Customer Data: our email provider, in the reports and alerts you asked us to send, and our error-monitoring provider, only incidentally, when an error message names something from your account.
1. Sub-processors of Customer Data
Customer Data is what the DPA covers: your Assets, Scans, Findings, evidence and Reports. These processors handle it on our behalf.
| Sub-processor | What it does | What it receives | Where |
|---|---|---|---|
| Google Cloud Platform (Google) | hosting on Cloud Run, the Cloud SQL database, Secret Manager, the private evidence store | all Customer Data, encrypted in transit and at rest | asia-south1 (Mumbai) |
| Google Cloud Vertex AI (Google) | model inference for validation and report writing | normalised, minimised and redacted Finding fields only (DPA §6); never a credential or a raw request or response | asia-south1 (Mumbai) |
| Mailtrap (Railsware Products Studio LLC) | transactional email: password resets, invitations, reports, alerts | the recipient's address and the message. A scan-report email attaches the full PDF Report; an alert carries the host, and finding titles and severities; an invoice email attaches the invoice | EU and US |
| Sentry (Functional Software, Inc.) | error monitoring: reports of errors in the SecQon web app, the API and the scan workers, so we learn of a failure before you have to tell us | the error message and stack trace, the page or API route it happened on, the release, and the browser and operating system. Sentry works out an approximate location (country and city) from the connection and does not store the address. An error message can incidentally name an Asset's host or a Finding's title. It is not sent IP addresses, cookies, request or response bodies, stored credentials or evidence, and session recording is off | EU (Germany) |
2. Other processors
These process personal data for which we are the controller, not Customer Data. We list them because a security review asks, and the answer should be on the same page.
| Processor | What it does | What it receives | Where |
|---|---|---|---|
| Razorpay (Razorpay Software Private Limited) | payment gateway. It hosts the checkout window and takes card details directly | the payer's name and email, which pre-fill the checkout, and the amount. Card and bank details are entered into Razorpay's window and never reach us | India |
| Google Tag Manager, Google Analytics, Google Ads (Google LLC) | marketing-site analytics and ad conversion measurement | page views and conversion events, only after you consent in the banner | global |
| LinkedIn (LinkedIn Ireland Unlimited Company or LinkedIn Corporation) | LinkedIn ad conversion measurement (the Insight Tag) | on our public pages: the pages viewed and the buttons and links clicked, with their text; which conversions happened (a trial or purchase inside the app is reported by an image request naming the conversion, and nothing else from the page). Only after you consent in the banner. Its script is refused by the browser inside the signed-in app, so it never sees Customer Data | global |
| Google reCAPTCHA (Google LLC) | bot protection on the sign-up, log-in, password-reset and free-check forms | browser and device characteristics and interaction with the page, collected by Google's script on those forms; from our server, the form's one-time token only | global |
3. What is not on this list, and why
- Your own destinations. A Slack workspace, webhook endpoint or email address you point an alert rule at receives what you configured it to. We send it there on your instruction; that destination is yours, not our sub-processor.
- People you share a Report with. A share link gives the Report to whoever holds it, by your choice.
- The systems we test. Scan traffic goes only to Assets you have verified. They are yours, and the Rules of Engagement govern that traffic.
4. How we tell you about a change
Before we add or replace a sub-processor of Customer Data (Section 1), we email the owners of every organisation and update this page. The change takes effect only after that notice. DPA §7.3 gives you the right to object and says what happens if you do. Where the GDPR applies, the notice period is the one in the GDPR and UK Data Protection Addendum.
A change to Section 2 is recorded below and in the Privacy Policy. We do not email about it, because it does not touch Customer Data.
Questions: legal@secqon.com.
5. Change log
- 2026-09-28 — LinkedIn (Insight Tag, consent-gated, public pages only) and Google reCAPTCHA (bot protection on the public forms) added to Section 2. Neither processes Customer Data, so no notice was owed; recorded here and in Privacy Policy 2026-09-v11.
- 2026-09-25 — Sentry's row now says it records an approximate location (country and city) worked out from the connection. No sub-processor added or removed.
- 2026-09-25 — Sentry (Functional Software, Inc.) added as a sub-processor of Customer Data, for error monitoring, processing in the EU (Germany). No customer organisation existed yet, so there was no one to notify and it took effect on publication.
- 2026-09-24 — This page published. It lists the same sub-processors as DPA §7, with what each one receives. No sub-processor added or removed.
- 2026-09-22 — DPA 2026-09-v1 published with its sub-processor list.
- 2026-09-19 — Razorpay became the payment gateway directly, and the Infiqon group billing service that had handled payment before was retired.