Trust & Disclosure

Sub-processors

The third parties that may process customer data on behalf of Onyx Security Labs. Maintained per the HIPAA Business Associate Agreement chain and GDPR Article 28(2) sub-processor disclosure obligations.

Active sub-processors

Who may process customer data.

We notify customers of changes to this list at least 30 days in advance. Customers whose engagement includes personal data, Protected Health Information, or cardholder data may request an audit of any listed sub-processor under their Data Processing Agreement. Specific named vendors are confirmed in your signed agreement.

Sub-processorPurposeLocationData accessed
Security delivery partnerCompliance assessment delivery, penetration testing (including cloud-based network and server testing), vulnerability scanning, DPO services (delivered remotely and virtually), and customised policy and procedure developmentPakistanCustomer-scoped PHI, PII, and cardholder data per signed SOW
Approved Scanning Vendor (PCI ASV partner)Quarterly external vulnerability scans for PCI DSS. Routed via partner when the client has no existing ASV; skipped when the client supplies their ownUSAExternal-facing IP addresses and asset metadata only
QSA partner (engaged per client)QSA-signed PCI DSS Report on Compliance or Attestation of Compliance for Level 1 merchants and service providers, where a Qualified Security Assessor is mandatoryUSA / GlobalCustomer-scoped cardholder data environment evidence per signed SOW
IAF-accredited certification partnerStage 1 and Stage 2 certification audits and certificate issuance for ISO/IEC 27001, ISO 22301, ISO/IEC 20000-1, and ISO 14001GlobalManagement-system documentation and audit evidence per signed SOW
CREST-member testing partnerCREST-accredited penetration testing where a CREST requirement appliesUSA / UK / GlobalCustomer-scoped technical testing data per signed SOW
Payment processorCustomer billing and payment processingUSACustomer billing metadata
Email and document collaboration providerEmail, calendar, and document collaborationUSACustomer communications and shared documents
Static website hostHosting of this public websiteUSA / GlobalPublic website data only; no customer data flows through hosting
Scheduling providerScope-call schedulingUSA / EUMeeting scheduling data and contact email only
E-signature providerMSA, SOW, BAA, and DPA executionUSAContract metadata and signature data
Disclosure Stance

Why this list is public.

Our contractual frameworks require us to disclose sub-processors. HIPAA Business Associate Agreements require flowdown to subcontractors under 45 CFR ยง164.504(e)(5). GDPR Article 28(2) requires processor authorization for sub-processors. US state privacy laws similarly require service-provider disclosures.

We could provide this list privately on request. We publish it because our first value is transparency by default. Customers, prospects, and regulators can review our supply chain without needing to ask.

Customers may object to a specific sub-processor in writing within 30 days of notification. If we cannot resolve the objection through reasonable alternatives, the customer may terminate the affected services without penalty per their Master Service Agreement.

Ready to simplify security and compliance?

Pick a service, book a scope call, or ask a question. Whatever order works.