Skip to main content
Threatstealth
Login

Subprocessors

Last updated: May 16, 2026

Threatstealth uses the following sub-processors to deliver the platform. We notify customers at least 30 days before adding a new sub-processor. You can object to new sub-processors during this window as described in our DPA.

Sub-processorCountryPurposePrivacy
Amazon Web Services (AWS)USA / EU (eu-west-1)Cloud infrastructure — compute, storage, database, networkingPolicy →
CloudflareUSA / GlobalDDoS mitigation, DNS, TLS termination, WAF edge layerPolicy →
SendGrid (Twilio)USATransactional email delivery (alerts, notifications)Policy →
StripeUSA / EUPayment processing and subscription billingPolicy →
DatadogUSA / EUInfrastructure monitoring, APM, log aggregationPolicy →
PagerDutyUSAOn-call alerting and incident management escalationPolicy →
WorkOSUSAEnterprise SSO (SAML/OIDC) and SCIM provisioningPolicy →
GitHub (Microsoft)USASource code hosting and CI/CDPolicy →
NVD / NISTUSA (US Government)CVE and vulnerability data (read-only public API)Policy →
OpenSearch (self-hosted)Customer regionSIEM log aggregation (self-hosted within customer VPC)Policy →

Questions about sub-processors: privacy@threatstealth.com