Skip to content

Sub-processors

HarborGuard engages a small set of sub-processors to operate the service. This page is the canonical public list. We commit to giving customers 30 days' written notice before adding a new sub-processor that processes customer personal data.

Active sub-processors

Sub-processorPurposeData categoryRegion
Fly.io, Inc.Application hosting, compute, managed Postgres, object storageAll customer data at rest and in transitUS (primary)
Stripe, Inc.Subscription billing, invoicing, payment-method storageBilling contact, plan and usage metadata; card data is collected directly by Stripe and never touches HarborGuard infrastructureUS, with EU sub-processors per Stripe's own DPA
Twilio SendGridTransactional and notification email delivery (account verification, password reset, billing receipts, notification emails)Recipient email address, message subject and body (notification metadata; not scan contents)US

HarborGuard does not transmit your scan contents, SBOMs, or vulnerability findings to any third party except as required to deliver the service (for example, sending a notification email containing a finding summary that the customer has explicitly configured). We do not currently use a third-party error-tracking or observability vendor; if that changes, this page will be updated and notice will go out per the policy below.

Sub-processors used only on customer instruction

These vendors only receive customer data when the customer explicitly configures an integration:

Sub-processorTriggerData category
Slack TechnologiesCustomer enables a Slack notification channelNotification payload (finding summary, links)
PagerDutyCustomer enables a PagerDuty notification channelIncident payload (severity, finding summary)
Customer-configured webhook endpointsCustomer registers a webhookWhatever the customer subscribes to; payload is HMAC-signed
Customer-configured SSO IdP (Okta, Azure AD, Google Workspace, generic SAML / OIDC)Customer enables SSOAuthentication assertions, group memberships

Notification of changes

To subscribe to sub-processor change notifications:

  • Existing customers: notifications go to the workspace's billing-contact email automatically.
  • Prospects and security teams: email trust@harborguard.co to be added to the announcement list.

Customer objection right

Customers may object to a new sub-processor within 30 days of notice. If we cannot offer an alternative, customers may terminate the affected service per the Master Subscription Agreement.

On this page