HackerSec
Trust Status Terms
Terms of Use Privacy Acceptable Use Sub-processors
Contents
1. Overview 2. Current List 3. Updates 4. Contact

Sub-processors

Last updated: July 14, 2026 · Version: 1.1
Changes in this version: Editorial revision: terminology standardized to Platform and Operations, with no change to rights or obligations.

1. Overview

This page lists the sub-processors engaged by HackerSec in the operation of the HAS — HackerSec Advanced Security platform. Sub-processors are third-party companies that process personal or technical Client data on behalf of HackerSec, supporting the operation of the Platform.

This disclosure fulfills HackerSec's obligations under the GDPR (Art. 28.2) and applicable data protection law, allowing Clients to evaluate the processing chain of their data.

All sub-processors are contractually bound by data protection obligations equivalent to those undertaken by HackerSec toward its Clients, as detailed in Section 11 of the Privacy Policy.

2. Sub-processor Categories

Last updated: May 3, 2026

The table below presents the categories of sub-processors used, their purposes and data locations. Specific provider names within each category are made available to the Client upon execution of a Non-Disclosure Agreement (NDA), together with the relevant data processing agreements.

Category Purpose Data Location
Cloud Provider Platform hosting, compute and storage United States
AI / LLM Provider AI models powering testing operations (Yaga), with restricted retention controls United States
CDN / WAF Content delivery, DDoS protection and Web Application Firewall Global
Payment Processing Financial transactions (credit card, PIX, boleto) United States and European Union
Transactional Email Operational notifications and Client communication United States and European Union

Access to nominal list: Clients requiring specific sub-processor names for internal audit, compliance or Vendor Security Assessment purposes may request the detailed list by emailing [email protected], upon execution of a standard NDA.

3. List Updates

HackerSec may add, replace or remove sub-processors as the Platform evolves and operational needs change.

Prior notice: changes to the sub-processors list will be published on this page at least 30 (thirty) days before becoming effective, except in cases of security urgency, operational necessity, vendor discontinuation or replacement, or legal requirement, in which case notification will be provided as soon as practicable.

Subscribe to notifications: Clients who wish to receive email notifications about changes to this list may request enrollment by writing to [email protected] with the subject "Sub-processor Notifications".

Right to object: if the Client has a substantiated objection to the addition of a new sub-processor, they must notify HackerSec within the prior notice period. HackerSec may, at its discretion, evaluate the request individually and, where technical accommodation is not feasible, explore commercial alternatives.

4. Contact

For questions about sub-processors or to exercise your rights as a data subject regarding third-party processing:

HackerSec Inovação em Cibersegurança Ltda.

Privacy and Data Subject Rights (DPO): [email protected]

General: [email protected]

Website: hackersec.com/contato

Address: Avenida Ipanema, 165, Dezoito do Forte Empresarial/Alphaville, Barueri, SP, 06472-002, Brazil

© 2026 HackerSec Inovação em Cibersegurança Ltda.

Trust Trust and Security Status
Legal Terms of Use Privacy Acceptable Use Sub-processors Code of Ethics
Security security.txt Report Vulnerability Contact