Subprocessors
SecuryxAI uses the following third-party subprocessors to deliver the platform. We maintain data processing agreements with each.
Current Subprocessors
| Provider | Purpose | Data Processed | Region | Certification |
|---|---|---|---|---|
| Supabase | Database hosting and backend infrastructure | All platform data including user accounts, compliance content, evidence, audit logs | United States (AWS us-east-1) | SOC 2 Type II |
| Vercel | Application hosting, edge network, and CDN | Request metadata, application logs, cached responses | Global edge network (primary: US East) | SOC 2 Type II |
| OpenAI | AI-powered questionnaire analysis and control mapping | Questionnaire text, question content, control names and descriptions (no personal data beyond context) | United States | SOC 2 Type II |
| Microsoft 365 | Internal team communications and productivity | SecuryxAI team data only — no customer personal data is processed | United States | ISO 27001, SOC 2 |
| Resend | Transactional email delivery | Recipient name and email address, email content (password resets, security alerts, notifications) | United States | SOC 2 Type II |
Data Transfer Mechanisms
All subprocessors that process personal data of EU/EEA or UK residents do so under appropriate transfer mechanisms:
- Supabase: Standard Contractual Clauses (EU SCCs, Module 3)
- Vercel: Standard Contractual Clauses + EU-US Data Privacy Framework
- OpenAI: Standard Contractual Clauses
- Microsoft 365: Standard Contractual Clauses + EU-US Data Privacy Framework
- Resend: Standard Contractual Clauses
AI Processing Note
When you use SecuryxAI’s AI-powered questionnaire analysis features, questionnaire text and control descriptions are sent to OpenAI for processing. We configure OpenAI API calls with zero data retention — OpenAI does not retain API inputs beyond the request and does not use them to train models. We avoid including personally identifiable information in AI prompts where possible.
How We Select Subprocessors
All subprocessors are vetted against our Supplier Security Requirements before onboarding. We require:
- SOC 2 Type II report or equivalent (ISO 27001 certification)
- A signed Data Processing Agreement
- Confirmation of GDPR compliance measures
- Appropriate breach notification procedures
How to Get Notified of Changes
Subprocessor change notifications are sent to the account owner email address on file. If you would like a specific email address to receive notifications, contact privacy@securyxai.com.
Contact
Questions about our subprocessors or data transfers: privacy@securyxai.com