Sub-processors
The third parties that may process customer data on behalf of Onyx Security Labs. Maintained per the HIPAA Business Associate Agreement chain and GDPR Article 28(2) sub-processor disclosure obligations.
Who may process customer data.
We notify customers of changes to this list at least 30 days in advance. Customers whose engagement includes personal data, Protected Health Information, or cardholder data may request an audit of any listed sub-processor under their Data Processing Agreement. Specific named vendors are confirmed in your signed agreement.
| Sub-processor | Purpose | Location | Data accessed |
|---|---|---|---|
| Security delivery partner | Compliance assessment delivery, penetration testing (including cloud-based network and server testing), vulnerability scanning, DPO services (delivered remotely and virtually), and customised policy and procedure development | Pakistan | Customer-scoped PHI, PII, and cardholder data per signed SOW |
| Approved Scanning Vendor (PCI ASV partner) | Quarterly external vulnerability scans for PCI DSS. Routed via partner when the client has no existing ASV; skipped when the client supplies their own | USA | External-facing IP addresses and asset metadata only |
| QSA partner (engaged per client) | QSA-signed PCI DSS Report on Compliance or Attestation of Compliance for Level 1 merchants and service providers, where a Qualified Security Assessor is mandatory | USA / Global | Customer-scoped cardholder data environment evidence per signed SOW |
| IAF-accredited certification partner | Stage 1 and Stage 2 certification audits and certificate issuance for ISO/IEC 27001, ISO 22301, ISO/IEC 20000-1, and ISO 14001 | Global | Management-system documentation and audit evidence per signed SOW |
| CREST-member testing partner | CREST-accredited penetration testing where a CREST requirement applies | USA / UK / Global | Customer-scoped technical testing data per signed SOW |
| Payment processor | Customer billing and payment processing | USA | Customer billing metadata |
| Email and document collaboration provider | Email, calendar, and document collaboration | USA | Customer communications and shared documents |
| Static website host | Hosting of this public website | USA / Global | Public website data only; no customer data flows through hosting |
| Scheduling provider | Scope-call scheduling | USA / EU | Meeting scheduling data and contact email only |
| E-signature provider | MSA, SOW, BAA, and DPA execution | USA | Contract metadata and signature data |
Why this list is public.
Our contractual frameworks require us to disclose sub-processors. HIPAA Business Associate Agreements require flowdown to subcontractors under 45 CFR ยง164.504(e)(5). GDPR Article 28(2) requires processor authorization for sub-processors. US state privacy laws similarly require service-provider disclosures.
We could provide this list privately on request. We publish it because our first value is transparency by default. Customers, prospects, and regulators can review our supply chain without needing to ask.
Customers may object to a specific sub-processor in writing within 30 days of notification. If we cannot resolve the objection through reasonable alternatives, the customer may terminate the affected services without penalty per their Master Service Agreement.
Ready to simplify security and compliance?
Pick a service, book a scope call, or ask a question. Whatever order works.