SUB-PROCESSORS

Third-Party Sub-processors

Normos Technologies Ltd engages the following third-party sub-processors to deliver the Normos.io platform. All sub-processors are bound by data protection obligations no less onerous than those in our Data Processing Agreement.

Last updated: 16 May 2026 — 7 sub-processors

30-day change notice. In accordance with our Data Processing Agreement, Normos Technologies Ltd will provide at least 30 days' written notice before adding or replacing any sub-processor. Customers may object to changes in writing within 14 days. To receive change notifications, email [email protected] to be added to our sub-processor notification list.

Supabase

Infrastructure
View DPA →

Database, authentication, and storage for app.normos.io. Hosts all customer data including Forensic Findings, scan runs, audit logs, and encrypted OAuth tokens.

Data Location

EU — Republic of Ireland (AWS eu-west-1)

Certifications

SOC 2 Type II, GDPR compliant, ISO 27001

Vercel

Infrastructure
View DPA →

Platform hosting and global edge network for both normos.io (landing page) and app.normos.io (dashboard). Handles all HTTP requests, server-side rendering, and API routes.

Data Location

Global edge network — EU nodes available

Certifications

SOC 2 Type II, ISO 27001, GDPR compliant

Cloudflare

Infrastructure
View DPA →

DNS, CDN, WAF, DDoS protection, and bot management for normos.io and app.normos.io. All traffic passes through Cloudflare before reaching Vercel.

Data Location

Global edge network — EU nodes available

Certifications

ISO 27001, SOC 2 Type II, GDPR compliant

Resend

Communications
View DPA →

Transactional email delivery for platform notifications including invitations, password resets, MFA enrolment, and pilot application confirmations.

Data Location

US — using Amazon SES EU Ireland infrastructure

Certifications

SOC 2 Type II, GDPR compliant

GitHub

Integration
View DPA →

OAuth provider for read-only integration with customer GitHub organisations. No data is stored from GitHub beyond the OAuth access token, which is encrypted at rest.

Data Location

US

Certifications

SOC 2 Type II, ISO 27001, GDPR compliant

Cloudflare Turnstile

Security
View DPA →

Bot and abuse protection on authentication forms (login and password reset). Processes IP addresses and browser fingerprints to distinguish humans from bots.

Data Location

US — Cloudflare infrastructure

Certifications

GDPR compliant, CCPA compliant

Amazon Web Services

Infrastructure
View DPA →

Email infrastructure via Amazon SES, used by Resend for email delivery. Also the underlying infrastructure for Supabase EU Ireland deployment.

Data Location

EU — eu-west-1 (Ireland)

Certifications

ISO 27001, SOC 2 Type II, ISO 42001, GDPR compliant

Attio

Business Operations
View DPA →

Customer relationship management (CRM). Processes contact names, email addresses, and company names of Normos prospects and customers for sales and account management purposes.

Data Location

EU — London, United Kingdom

Certifications

GDPR compliant, SOC 2 Type II

BoldSign

Business Operations
View DPA →

Electronic document signing for Pilot Agreements, NDAs, and other legal documents. Processes names, email addresses, and signed document content of signatories.

Data Location

EU — Netherlands data centre

Certifications

GDPR compliant, eIDAS compliant, SOC 2 Type II

Calendly

Business Operations
View DPA →

Meeting scheduling for product demos and pilot feedback calls. Processes names, email addresses, and meeting metadata of prospects and customers who book calls.

Data Location

US — with GDPR-compliant data handling for EU data subjects

Certifications

GDPR compliant, SOC 2 Type II

Primary Data Residency

All primary customer data — including Forensic Findings, scan runs, audit logs, and encrypted OAuth tokens — is stored in the European Union, Republic of Ireland (AWS eu-west-1) via Supabase. This data never leaves EU jurisdiction under normal platform operation.

Email communications (via Resend) are routed through Amazon SES infrastructure in EU Ireland. Cloudflare and Vercel process request data at their global edge nodes — this is standard for any cloud-hosted web application.

Questions

For questions about our sub-processors or data processing practices, contact [email protected]. For security concerns, contact [email protected].