SUB-PROCESSORS
Third-Party Sub-processors
Normos Technologies Ltd engages the following third-party sub-processors to deliver the Normos.io platform. All sub-processors are bound by data protection obligations no less onerous than those in our Data Processing Agreement.
30-day change notice. In accordance with our Data Processing Agreement, Normos Technologies Ltd will provide at least 30 days' written notice before adding or replacing any sub-processor. Customers may object to changes in writing within 14 days. To receive change notifications, email [email protected] to be added to our sub-processor notification list.
Supabase
InfrastructureDatabase, authentication, and storage for app.normos.io. Hosts all customer data including Forensic Findings, scan runs, audit logs, and encrypted OAuth tokens.
Data Location
EU — Republic of Ireland (AWS eu-west-1)
Certifications
SOC 2 Type II, GDPR compliant, ISO 27001
Vercel
InfrastructurePlatform hosting and global edge network for both normos.io (landing page) and app.normos.io (dashboard). Handles all HTTP requests, server-side rendering, and API routes.
Data Location
Global edge network — EU nodes available
Certifications
SOC 2 Type II, ISO 27001, GDPR compliant
Cloudflare
InfrastructureDNS, CDN, WAF, DDoS protection, and bot management for normos.io and app.normos.io. All traffic passes through Cloudflare before reaching Vercel.
Data Location
Global edge network — EU nodes available
Certifications
ISO 27001, SOC 2 Type II, GDPR compliant
Resend
CommunicationsTransactional email delivery for platform notifications including invitations, password resets, MFA enrolment, and pilot application confirmations.
Data Location
US — using Amazon SES EU Ireland infrastructure
Certifications
SOC 2 Type II, GDPR compliant
GitHub
IntegrationOAuth provider for read-only integration with customer GitHub organisations. No data is stored from GitHub beyond the OAuth access token, which is encrypted at rest.
Data Location
US
Certifications
SOC 2 Type II, ISO 27001, GDPR compliant
Cloudflare Turnstile
SecurityBot and abuse protection on authentication forms (login and password reset). Processes IP addresses and browser fingerprints to distinguish humans from bots.
Data Location
US — Cloudflare infrastructure
Certifications
GDPR compliant, CCPA compliant
Amazon Web Services
InfrastructureEmail infrastructure via Amazon SES, used by Resend for email delivery. Also the underlying infrastructure for Supabase EU Ireland deployment.
Data Location
EU — eu-west-1 (Ireland)
Certifications
ISO 27001, SOC 2 Type II, ISO 42001, GDPR compliant
Attio
Business OperationsCustomer relationship management (CRM). Processes contact names, email addresses, and company names of Normos prospects and customers for sales and account management purposes.
Data Location
EU — London, United Kingdom
Certifications
GDPR compliant, SOC 2 Type II
BoldSign
Business OperationsElectronic document signing for Pilot Agreements, NDAs, and other legal documents. Processes names, email addresses, and signed document content of signatories.
Data Location
EU — Netherlands data centre
Certifications
GDPR compliant, eIDAS compliant, SOC 2 Type II
Calendly
Business OperationsMeeting scheduling for product demos and pilot feedback calls. Processes names, email addresses, and meeting metadata of prospects and customers who book calls.
Data Location
US — with GDPR-compliant data handling for EU data subjects
Certifications
GDPR compliant, SOC 2 Type II
Primary Data Residency
All primary customer data — including Forensic Findings, scan runs, audit logs, and encrypted OAuth tokens — is stored in the European Union, Republic of Ireland (AWS eu-west-1) via Supabase. This data never leaves EU jurisdiction under normal platform operation.
Email communications (via Resend) are routed through Amazon SES infrastructure in EU Ireland. Cloudflare and Vercel process request data at their global edge nodes — this is standard for any cloud-hosted web application.
Questions
For questions about our sub-processors or data processing practices, contact [email protected]. For security concerns, contact [email protected].