The third parties that process data on our behalf — and yours.
A complete list of the vendors ScanPosture relies on, their purpose, the categories of data they touch, and the region in which they process it.
Grouped by where data is processed
The order matters. Customer data lives in the UK; everything else is operational tooling routed through Europe. Two vendors don’t see customer data at all.
Supabase
United Kingdom (London, eu-west-2)
Primary database, authentication backend and storage
All customer-tenant data — accounts, scan results, findings, audit logs, billing references
Postgres + Row-Level Security; AES-256 at rest at the storage layer.
Vercel
EU regions; UK / EU traffic served from EU edge
Application hosting, serverless compute, scheduled jobs
Request metadata, application logs, build artefacts. No customer data persisted at the edge.
Resend
EU / US (recipient address only on the receiving leg)
Transactional email delivery (account, scan summaries, alerts)
Recipient email address, message subject, message body, delivery status
Stripe
EU / US (Stripe data residency model)
Subscription billing and payment processing
Billing-account email, invoice history, card token (handled by Stripe — never stored by ScanPosture). Per-month seat counts pushed from completed scans.
Plausible Analytics
European Union (Plausible is EU-hosted)
Cookieless web analytics on the public marketing site only
Page views, referrer, anonymised location at country level. No cookies, no individual identifiers.
Public marketing site (scanposture.com) only. Not loaded inside the customer application.
Cloudflare
Global edge network
DNS, edge proxy, Turnstile bot challenge on signup forms
Request metadata only. Turnstile receives a session token, not user-entered fields.
Microsoft (Graph + Exchange Online + SharePoint Online)
Customer’s own Microsoft tenant region
Read-only assessment of customer Microsoft 365 / Entra ID configuration
Configuration metadata only — read-only Graph, Exchange and SharePoint admin scopes. No mailbox or document content. No write actions.
Microsoft is the customer’s own primary processor; ScanPosture acts on the customer’s behalf via admin consent.
GitHub
United States
Source-code hosting, CI/CD pipelines (deploy workflows)
Source code only. No production customer data is ever stored in or transmitted via GitHub.
Change notification
We notify customers of changes to this list in advance, as required by the ScanPosture Data Processing Agreement. Customers may object to a proposed sub-processor change in line with the terms set out in the DPA. Questions about this list? hello@scanposture.com.