Skip to content
← Legal

Subprocessors

Effective: Last updated:

This page lists the third-party subprocessors Fimil, Inc. engages to Process Customer Personal Data in connection with the Service, as referenced in our Data Processing Agreement and Privacy Policy. We impose data-protection obligations on each subprocessor that are no less protective than those in our DPA.

Subprocessors that process customer data

SubprocessorRoleLocationReference
DigitalOceanCloud infrastructure: compute, Kubernetes, managed PostgreSQL, container registry, and backup storageUnited StatesDPA
CloudflareCDN, DNS, edge security, and cookieless traffic analyticsGlobal (anycast)DPA
AnthropicLLM inference for AI-assisted features (penetration-test agent reasoning, finding triage, remediation suggestions, security chat)United StatesTerms
StripePayment processing and billingUnited StatesDPA
GitHubSource-code integration (OAuth/App), CI/CD, and pull-request automationUnited StatesDPA
GitLabSource-code integration (OAuth)United StatesPrivacy
Atlassian (Bitbucket)Source-code integration (OAuth)GlobalDPA
ResendTransactional email deliveryUnited StatesDPA
PostHogProduct analytics (consent-gated)United StatesDPA
TelegramOperational alert delivery for security/scope eventsGlobalPrivacy

An alternative LLM provider, DigitalOcean Gradient AI (United States), may be configured in place of Anthropic for self-hosted deployments. It is covered by the DigitalOcean DPA above.

Services that do not process customer personal data

For transparency, the Service also relies on the following third parties, which do not receive Customer Personal Data:

  • FIRST.org (EPSS) — vulnerability exploit-probability lookups by CVE identifier only.
  • PyPI and Docker Hub — public distribution of software packages and scanner container images.

Changes and notice

We will update this page when we add or replace a subprocessor. Customers under our DPA may subscribe to notice of changes and may object on reasonable data-protection grounds as described in the Data Processing Agreement. Questions: privacy@fimil.dev.