Our Data Processing Addendum commits us to maintaining a current list of the third parties that process data on your behalf, and to giving notice before that list changes. This is that list.
These providers are involved in running HexaSentra itself and may process your account data.
| Provider | Purpose | Data it can process | Location |
|---|---|---|---|
| DigitalOcean | Application servers and the primary database | All account and scan data at rest | India (Bangalore) |
| Vercel | Hosting for this marketing website | Request logs and IP addresses of site visitors only — no account or scan data | Global edge |
| Razorpay | Payment processing | Billing contact and payment details. Card details go directly to Razorpay; we never receive or store them | India |
| Resend | Transactional email (password resets, invitations, alerts) | Recipient email address and message content | United States |
| Hostinger | Inbound email for our published addresses | Anything you choose to send us by email | EU / Global |
Attack-surface discovery works partly by querying public records. When it does, the hostname you authorized us to scan is sent to the source below. No account details, credentials, or findings are ever shared with them.
| Source | What it is | What it receives |
|---|---|---|
| crt.sh | Certificate Transparency log search | Your domain name |
| Cert Spotter (SSLMate) | Certificate Transparency monitoring | Your domain name |
| subdomain.center | Passive subdomain dataset | Your domain name |
| HackerTarget | Passive reverse-IP and DNS data | Your domain name or IP |
| RDAP registries | Domain registration records | Your domain name |
| Google Public DNS | DNS resolution during discovery | Hostnames being resolved |
We download vulnerability intelligence in bulk and match it locally. These providers receive nothing about you — not even your domain.
These are off by default and involve a third party only because you connected it:
The AI Security Analyst runs entirely on our own infrastructure against your stored data. No customer data — no findings, assets, hostnames, or evidence — is sent to any external AI or large-language-model provider. There is no OpenAI, Anthropic, Google, or similar provider in the processing chain.
This website loads its typefaces from Google Fonts, which means Google receives the IP address of visitors to these pages. No cookies are set and no account data is involved. See our Cookie Policy.
We give notice before adding a sub-processor that would process customer data, and you may raise a reasonable objection as described in the DPA. To be notified of changes, email privacy@hexasentra.com.