Skip to content
SECQON

SecQon Sub-processors

Effective date: 28 September 2026 · Version: 2026-09-v4

This page lists every third party that processes personal data when you use SecQon. It is the list that Data Processing Agreement §7 authorises, kept where it can change without re-issuing the DPA. The change log at the bottom records each change.

The list is short, by design. Customer Data is hosted and model inference runs in Google Cloud's asia-south1 (Mumbai) region. Outside Google, two processors can see Customer Data: our email provider, in the reports and alerts you asked us to send, and our error-monitoring provider, only incidentally, when an error message names something from your account.

1. Sub-processors of Customer Data

Customer Data is what the DPA covers: your Assets, Scans, Findings, evidence and Reports. These processors handle it on our behalf.

Sub-processorWhat it doesWhat it receivesWhere
Google Cloud Platform (Google)hosting on Cloud Run, the Cloud SQL database, Secret Manager, the private evidence storeall Customer Data, encrypted in transit and at restasia-south1 (Mumbai)
Google Cloud Vertex AI (Google)model inference for validation and report writingnormalised, minimised and redacted Finding fields only (DPA §6); never a credential or a raw request or responseasia-south1 (Mumbai)
Mailtrap (Railsware Products Studio LLC)transactional email: password resets, invitations, reports, alertsthe recipient's address and the message. A scan-report email attaches the full PDF Report; an alert carries the host, and finding titles and severities; an invoice email attaches the invoiceEU and US
Sentry (Functional Software, Inc.)error monitoring: reports of errors in the SecQon web app, the API and the scan workers, so we learn of a failure before you have to tell usthe error message and stack trace, the page or API route it happened on, the release, and the browser and operating system. Sentry works out an approximate location (country and city) from the connection and does not store the address. An error message can incidentally name an Asset's host or a Finding's title. It is not sent IP addresses, cookies, request or response bodies, stored credentials or evidence, and session recording is offEU (Germany)

2. Other processors

These process personal data for which we are the controller, not Customer Data. We list them because a security review asks, and the answer should be on the same page.

ProcessorWhat it doesWhat it receivesWhere
Razorpay (Razorpay Software Private Limited)payment gateway. It hosts the checkout window and takes card details directlythe payer's name and email, which pre-fill the checkout, and the amount. Card and bank details are entered into Razorpay's window and never reach usIndia
Google Tag Manager, Google Analytics, Google Ads (Google LLC)marketing-site analytics and ad conversion measurementpage views and conversion events, only after you consent in the bannerglobal
LinkedIn (LinkedIn Ireland Unlimited Company or LinkedIn Corporation)LinkedIn ad conversion measurement (the Insight Tag)on our public pages: the pages viewed and the buttons and links clicked, with their text; which conversions happened (a trial or purchase inside the app is reported by an image request naming the conversion, and nothing else from the page). Only after you consent in the banner. Its script is refused by the browser inside the signed-in app, so it never sees Customer Dataglobal
Google reCAPTCHA (Google LLC)bot protection on the sign-up, log-in, password-reset and free-check formsbrowser and device characteristics and interaction with the page, collected by Google's script on those forms; from our server, the form's one-time token onlyglobal

3. What is not on this list, and why

  • Your own destinations. A Slack workspace, webhook endpoint or email address you point an alert rule at receives what you configured it to. We send it there on your instruction; that destination is yours, not our sub-processor.
  • People you share a Report with. A share link gives the Report to whoever holds it, by your choice.
  • The systems we test. Scan traffic goes only to Assets you have verified. They are yours, and the Rules of Engagement govern that traffic.

4. How we tell you about a change

Before we add or replace a sub-processor of Customer Data (Section 1), we email the owners of every organisation and update this page. The change takes effect only after that notice. DPA §7.3 gives you the right to object and says what happens if you do. Where the GDPR applies, the notice period is the one in the GDPR and UK Data Protection Addendum.

A change to Section 2 is recorded below and in the Privacy Policy. We do not email about it, because it does not touch Customer Data.

Questions: legal@secqon.com.

5. Change log

  • 2026-09-28 — LinkedIn (Insight Tag, consent-gated, public pages only) and Google reCAPTCHA (bot protection on the public forms) added to Section 2. Neither processes Customer Data, so no notice was owed; recorded here and in Privacy Policy 2026-09-v11.
  • 2026-09-25 — Sentry's row now says it records an approximate location (country and city) worked out from the connection. No sub-processor added or removed.
  • 2026-09-25 — Sentry (Functional Software, Inc.) added as a sub-processor of Customer Data, for error monitoring, processing in the EU (Germany). No customer organisation existed yet, so there was no one to notify and it took effect on publication.
  • 2026-09-24 — This page published. It lists the same sub-processors as DPA §7, with what each one receives. No sub-processor added or removed.
  • 2026-09-22 — DPA 2026-09-v1 published with its sub-processor list.
  • 2026-09-19 — Razorpay became the payment gateway directly, and the Infiqon group billing service that had handled payment before was retired.