Legal
Sub-processors
Last updated 2026-05-24.
A "sub-processor" is a third party that processes customer personal data on our behalf. Resolute Security uses the providers below to operate the service. Each is bound by their own privacy and security commitments, plus contractual data-processing agreements (DPAs) with us where applicable.
Customers who have signed our DPA receive at least 30 days notice before we add or replace a sub-processor; you can subscribe to changes by emailing privacy@resolute-security.com.
Data storage
| Vendor | Role | Data | Region | Certifications |
|---|---|---|---|---|
Neon Neon, Inc. Their DPA ↗ | Managed Postgres — primary data store for all customer records. |
| US (AWS us-east-1) |
|
Infrastructure
| Vendor | Role | Data | Region | Certifications |
|---|---|---|---|---|
Fly.io Fly.io, Inc. Their DPA ↗ | Application + worker hosting (compute, networking). |
| US + EU (per app region) |
|
Upstash Upstash, Inc. Their DPA ↗ | Managed Redis — background-job queue + ephemeral rate-limit state. |
| US (AWS us-east-1) |
|
Cloudflare Cloudflare, Inc. Their DPA ↗ | CDN, DNS, DDoS mitigation, WAF in front of the application. |
| Global edge |
|
Email delivery
| Vendor | Role | Data | Region | Certifications |
|---|---|---|---|---|
Resend Resend, Inc. Their DPA ↗ | Transactional email delivery (magic links, alerts, digests, training). |
| US |
|
Payments
| Vendor | Role | Data | Region | Certifications |
|---|---|---|---|---|
Stripe Stripe, Inc. Their DPA ↗ | Payment processing, subscription management, invoicing. |
| US + EU |
|
Authentication
| Vendor | Role | Data | Region | Certifications |
|---|---|---|---|---|
Google LLC Their DPA ↗ | OAuth sign-in (only invoked when a user chooses Google sign-in). |
| US + global |
|
Microsoft Microsoft Corporation Their DPA ↗ | OAuth sign-in + M365 integration for connected tenants. |
| US + global |
|
Monitoring & observability
| Vendor | Role | Data | Region | Certifications |
|---|---|---|---|---|
Sentry Functional Software, Inc. Their DPA ↗ | Error and exception monitoring (stack traces + metadata only). |
| US |
|
Related documents
- Data Processing Addendum — the contractual basis on which we process customer data.
- Privacy Policy — what we collect, why, and your rights.
- Data subject rights — file an access, deletion, or correction request.