Skip to content

Subprocessor list

Last updated: 2026-05-03

This page lists every third party that processes personal data on Secruna's behalf, the purpose of the processing, the region where the processing takes place, and the legal mechanism by which international transfers (where applicable) are governed.

This page is referenced from the Data Processing Agreement template, the Privacy Policy, and the Terms of Service. It supersedes any subprocessor list named in those documents in case of conflict.


Secruna-controlled subprocessors

These are vendors we contract with directly. Personal data about your organisation flows to each of them as part of operating the Secruna service.

Subprocessor Purpose Region Transfer mechanism
Microsoft Azure (Microsoft Ireland Operations Ltd) Hosting: Container Apps for the API and frontend, Azure Database for PostgreSQL Flexible Server, Azure Cache for Redis, Key Vault for credential storage, Log Analytics for runtime logs. EU — Sweden Central EU adequacy (data resident in the EU)
Anthropic, PBC LLM-based classification of AI artefacts metadata. We send extracted facts (resource names, vendor, model identifiers, audit-log fragments) to Claude Sonnet to produce a draft Annex III classification. We do not send full artefact JSON or any prompt/completion content from your AI systems. United States EU Standard Contractual Clauses (SCCs); Anthropic publishes a DPA referencing the EU 2021/914 SCCs
Resend, Inc. Transactional email delivery (notifications, HITL alerts, password reset, invitations). Recipients are users you grant Secruna access to. United States EU SCCs
Functional Software, Inc. (Sentry) Error tracking for the API and frontend. Error events include request IDs, tenant IDs, user IDs, stack traces, and HTTP request metadata; we configure Sentry's PII scrubber to drop request bodies and headers by default. United States EU SCCs
Better Stack (Productlab Hungary Kft. / a CEE-incorporated entity) Uptime monitoring against api.secruna.com and app.secruna.com, plus the public status page at status.secruna.com. Probes hit /healthz; status page contents are public. EU EU adequacy

The list above represents every Secruna-controlled subprocessor as of the Last updated date. We do not engage casual or session-based vendors — every subprocessor on this list has a contract on file.


Controller-controlled subprocessors

When you connect a cloud provider (AWS, GCP, GitHub) or an AI platform (OpenAI, Anthropic, Databricks), Secruna reads metadata out of your account through credentials you provide. Those vendors process data as your subprocessor, not ours, and your existing relationship with them governs that processing.

Cloud / platform What flows Region Transfer mechanism
Amazon Web Services Outbound: STS AssumeRole, Bedrock list, SageMaker list, CloudTrail lookup. Inbound: artefact metadata returned to Secruna. Wherever your AWS account is provisioned Determined by your AWS contract
Google Cloud Platform Outbound: Vertex AI list, Notebooks list, Cloud Logging entries:list. Wherever your GCP project is provisioned Determined by your GCP contract
GitHub (Microsoft Corp.) Outbound: GitHub App API calls (Copilot seats, SBOM, code search, workflow YAML). Where your GitHub organisation is hosted (default US for github.com; EU for GitHub Enterprise EU) Determined by your GitHub contract
OpenAI, OpCo LLC Outbound: organisation admin API. United States Determined by your OpenAI contract
Anthropic, PBC (when used as a connector, not as our LLM subprocessor — see above) Outbound: organisation admin API. United States Determined by your Anthropic contract
Databricks, Inc. Outbound: workspace OIDC + REST API calls. Wherever your Databricks workspace is deployed Determined by your Databricks contract
Microsoft (Azure / M365 connectors) Outbound: Azure Resource Graph, Azure Activity Log, Power Platform admin API. Wherever your tenant is provisioned Determined by your Microsoft contract

Why we make this distinction. Banking procurement teams often want a single line in the DPA listing every vendor we use. The honest answer is: the vendors you connect us to are not ours to list as subprocessors — they are an extension of your own infrastructure that we read on your behalf. We acknowledge them above for completeness.


Subprocessor change procedure

We commit to the following process for adding, replacing, or removing a Secruna-controlled subprocessor:

  1. Notice. We post the proposed change to this page with a proposed_effective_date at least 30 days in the future.
  2. Email notification. All tenant administrators receive an email through Resend with a link to the proposed change.
  3. Objection window. Tenant administrators may object in writing to legal@secruna.com (TODO: confirm address) within the 30-day window. A reasoned objection triggers a discussion and, if unresolved, the right to terminate the affected service per the DPA's termination clause.
  4. Effective. If no objection blocks the change, the new subprocessor is added on the effective_date and this page is updated.

For replacement (e.g., switching email vendor) the same 30-day notice applies. For removal (sunsetting a subprocessor with no replacement), no objection mechanism is required because the change reduces, not expands, the data surface.

For emergency replacements (a subprocessor goes out of business or breaches its contract), we may add the replacement immediately and provide notice within 5 business days; the objection window then runs from the date of notice. We document any such use in the DPA's audit-rights section.


Historical changes

Date Change
2026-05-03 Sentry added (error tracking, Plan 28a).
2026-05-03 Better Stack added (uptime monitoring + status page, Plan 28b).
2026-05-03 Initial publication of this page.

TODO: review by counsel before sending to any customer.