Security

Subprocessors

Effective Date:

WASViking Subprocessors

As part of delivering our cybersecurity services, WASViking LLC may engage the following subprocessors. These third-party service providers may process limited technical data (such as domain names, IP addresses, certificate metadata) strictly to support hosting, scanning infrastructure, or secure communications.

We ensure that all subprocessors are contractually bound to comply with strict data protection standards and are listed in our Data Processing Agreement (DPA).

Subprocessor Service Provided Location International Transfer Safeguards Learn More
AWS (Amazon Web Services) Infrastructure Hosting United States SCCs / EU-US Data Privacy Framework Learn more
Cloudflare WAF, TLS, DNS Protection Global (US/EU) SCCs / EU-US DPF Learn more
MongoDB Atlas Database Services United States SCCs / EU-US DPF Learn more
OpenAI AI-assisted analysis features, including finding summarization and recommendations, assistant responses, login form analysis for authenticated scanning, and mobile assessment narratives United States SCCs / EU-US DPF Learn more
SendGrid (Twilio) Email Delivery (2FA, Notifications) United States SCCs / EU-US DPF Learn more
Stripe Payment Processing (Subscription Plans) United States EU-US Data Privacy Framework Learn more

Brazilian LGPD transfers

For transfers of personal data subject to the Brazilian LGPD, the safeguards identified above for European transfers do not by themselves replace the international-transfer mechanisms required by Brazilian law.

WASViking evaluates transfers subject to the LGPD under Article 33 of Law No. 13,709/2018 and Resolution CD/ANPD No. 19/2024, including the ANPD Standard Contractual Clauses where they are the applicable transfer mechanism.

WASViking uses the OpenAI API through a corporate account. Voluntary data sharing for model training is disabled. WASViking does not currently use Zero Data Retention or Modified Abuse Monitoring, so the standard OpenAI API data retention controls apply. AI-assisted analysis is part of how certain platform modules work and is not a separately optional processing path.

Third-party services on our websites and portal

Separately from the subprocessors above, the following services run on our public website or in the browser when you use the portal, and may process your IP address and related technical data: Google reCAPTCHA (abuse prevention on portal authentication pages), Google Maps and Google Fonts (public website), Cookie-Script (cookie consent management on the public website), and public content delivery networks that serve static assets. These services do not receive Customer Content.

This list may be updated as our infrastructure evolves. Customers will be notified at least 30 days in advance before a new subprocessor is added, and may object on reasonable grounds.

For any questions regarding subprocessors or data protection, contact us at [email protected].


This page is part of WASViking’s compliance with the GDPR, LGPD, and CCPA frameworks. For additional details, see our Terms of Service, Privacy Policy and Data Processing Agreement (DPA).

Questions about security or privacy?

Write to the team that owns the answer. Security reviews, data subject requests and contract questions each have a direct address.

Evaluating WASViking? Talk to our team and we will bring the right people to the call.