Subprocessors
Last updated: May 16, 2026
Threatstealth uses the following sub-processors to deliver the platform. We notify customers at least 30 days before adding a new sub-processor. You can object to new sub-processors during this window as described in our DPA.
| Sub-processor | Country | Purpose | Privacy |
|---|---|---|---|
| Amazon Web Services (AWS) | USA / EU (eu-west-1) | Cloud infrastructure — compute, storage, database, networking | Policy → |
| Cloudflare | USA / Global | DDoS mitigation, DNS, TLS termination, WAF edge layer | Policy → |
| SendGrid (Twilio) | USA | Transactional email delivery (alerts, notifications) | Policy → |
| Stripe | USA / EU | Payment processing and subscription billing | Policy → |
| Datadog | USA / EU | Infrastructure monitoring, APM, log aggregation | Policy → |
| PagerDuty | USA | On-call alerting and incident management escalation | Policy → |
| WorkOS | USA | Enterprise SSO (SAML/OIDC) and SCIM provisioning | Policy → |
| GitHub (Microsoft) | USA | Source code hosting and CI/CD | Policy → |
| NVD / NIST | USA (US Government) | CVE and vulnerability data (read-only public API) | Policy → |
| OpenSearch (self-hosted) | Customer region | SIEM log aggregation (self-hosted within customer VPC) | Policy → |
Questions about sub-processors: privacy@threatstealth.com
