Sub-Processors

This page lists all sub-processors that may process personal data on behalf of Disso Security.

Last updated: Dec 7, 2025
Sub-ProcessorProcessing ActivitiesLocation of Data Storage
Data Transfer Safeguards
DigitalOceanHosting infrastructure and cloud storage for application deploymentEU - Amsterdam / FrankfurtStandard Contractual Clauses (SCCs), Data Processing Agreement (DPA)
Microsoft AzureCloud infrastructure for compute, storage, and networking servicesEU - FranceStandard Contractual Clauses (SCCs), EU-US Data Privacy Framework, Microsoft DPA
CloudflareCDN / edge network / security / caching / traffic distribution / TLS termination / edge routingEU (with Regional Services / Data Localization Suite configured)Cloudflare Data Localization Suite (Regional Services + Geo Key Manager / Customer Metadata Boundary), ensures HTTPS-traffic processing and metadata stay within EU data centers. :contentReference[oaicite:3]{index=3}
Better StackMonitoring, error tracking, log management, alerting, incident & uptime managementEU (data stored in EU data centers by default) ✔ GDPR-compliant. :contentReference[oaicite:4]{index=4}SOC 2 Type II, GDPR compliance, ISO/IEC 27001-certified data centers, Data Processing Agreement (DPA) available. :contentReference[oaicite:5]{index=5}
IntercomCustomer support chat, messaging, and user engagement servicesEUStandard Contractual Clauses (SCCs), Data Processing Agreement (DPA), EU-US Data Privacy Framework
Jira (Atlassian)Ticketing, issue tracking, and project management involving user dataEUStandard Contractual Clauses (SCCs), Atlassian DPA, EU-US Data Privacy Framework
MistralProcessing user communications via GenAI modelsEU (France, as of 2024)Typically only EU-based processing; compliant with EU data protection standards
HubSpotCustomer relationship management, marketing automation, and user communicationsEUStandard Contractual Clauses (SCCs), HubSpot DPA, EU-US Data Privacy Framework
SlackInternal communication potentially involving user data (e.g., error logs)EUStandard Contractual Clauses (SCCs), Slack DPA, EU-US Data Privacy Framework
StripePayment processing and billing (if used)EU / US (depending on Stripe config)Stripe Data Processing Agreement (DPA), EU-US Data Privacy Framework and applicable contractual safeguards

About Sub-Processors

Disso Security engages certain third-party service providers to assist in providing our services. These entities process personal data on our behalf and are contractually bound to process data in accordance with our instructions and applicable data protection laws.

We implement appropriate technical and organizational measures to ensure that these sub-processors provide sufficient guarantees to protect your personal data. We regularly review and update this list to reflect any changes in our sub-processor relationships.

For more information about how we process personal data, please refer to our Privacy Policy.