Skip to content

Sub-processors

HarborGuard engages a small set of sub-processors to operate the service. This page is the canonical public list. We commit to giving customers 30 days' written notice before adding a new sub-processor that processes customer personal data.

Active sub-processors

Sub-processorPurposeData categoryRegion
Fly.io, Inc.Application hosting, compute, managed Postgres, object storageAll customer data at rest and in transitUS (primary)
Stripe, Inc.Subscription billing, invoicing, payment-method storageBilling contact, plan and usage metadata; card data is collected directly by Stripe and never touches HarborGuard infrastructureUS, with EU sub-processors per Stripe's own DPA
Twilio SendGridTransactional and notification email delivery (account verification, password reset, billing receipts, notification emails)Recipient email address, message subject and body (notification metadata; not scan contents)US
Intercom, Inc.Live chat / support widgetAnonymous visitor analytics + customer support messagesUS
Plausible Insights OÜPrivacy-friendly web analytics, loaded only when NEXT_PUBLIC_PLAUSIBLE_DOMAIN is configured in productionAnonymized visitor analytics: page URL, referrer, country-level location, user agent. No IP storage.Estonia (EU)
Google LLCWeb fonts (Google Fonts CDN)Visitor IP address and browser metadata at font request timeUS

HarborGuard does not transmit your scan contents, SBOMs, or vulnerability findings to any third party except as required to deliver the service (for example, sending a notification email containing a finding summary that the customer has explicitly configured). We do not currently use a third-party error-tracking or observability vendor; if that changes, this page will be updated and notice will go out per the policy below.

Sub-processors used only on customer instruction

These vendors only receive customer data when the customer explicitly configures an integration:

Sub-processorTriggerData category
Slack TechnologiesCustomer enables a Slack notification channelNotification payload (finding summary, links)
PagerDutyCustomer enables a PagerDuty notification channelIncident payload (severity, finding summary)
Customer-configured webhook endpointsCustomer registers a webhookWhatever the customer subscribes to; payload is HMAC-signed
Customer-configured SSO IdP (Okta, Azure AD, Google Workspace, generic SAML / OIDC)Customer enables SSOAuthentication assertions, group memberships

Notification of changes

To subscribe to sub-processor change notifications:

  • Existing customers: notifications go to the workspace's billing-contact email automatically.
  • Prospects and security teams: email trust@harborguard.co to be added to the announcement list.

Customer objection right

Customers may object to a new sub-processor within 30 days of notice. If we cannot offer an alternative, customers may terminate the affected service per the Master Subscription Agreement.

On this page