This page lists the sub-processors Stealed SAS engages to deliver its services, in accordance with Article 28 GDPR. It is kept up to date and complements our Privacy Policy.
The most important distinction on this page is between leak data and account data.
Leak data is the compromised credentials we collect, index and disclose. It is what constitutes the service, it is what is sensitive, and it is what we mean when we talk about sovereignty. It is hosted and processed in France, with a French infrastructure provider, with no exposure to extraterritorial legislation such as the CLOUD Act. Its encrypted backups are held there too. No leak data leaves French territory, and no sub-processor outside the European Union has access to it.
Account data is the data of Platform users: the name and business email address of an analyst who logs in, and the address a notification is sent to. Two peripheral functions process it, authentication and email delivery, and their providers host in the United States. The authentication provider does not offer hosting in the European Union; the transfer is governed by its EU-US Data Privacy Framework certification and by the European Commission's standard contractual clauses. Neither function involves any leak data.
| Provider | Role | Location | Transfer safeguard | Categories of data |
|---|---|---|---|---|
| Scaleway SAS | Cloud infrastructure, storage and backup provider | France — Paris region (fr-par), zones 1 and 2 | European Union | All Platform data, including leak data, and its backups |
| PostHog | Product usage analytics provider | Germany — Frankfurt (AWS eu-central-1) | European Union | Application usage events |
| Grafana Labs | Technical monitoring provider | United Kingdom — London (AWS eu-west-2) | UK adequacy decision | Technical operations logs |
| Cloudflare, Inc. | Content delivery and edge protection provider | Global network, European points of presence for European traffic. Company established in the United States | Standard contractual clauses | Request metadata, IP address |
| Clerk, Inc. | Authentication and account management provider | United States. This provider does not offer hosting in the European Union | EU-US Data Privacy Framework and standard contractual clauses | Platform user account data: name, business email address, organisation |
| Loops | Transactional email provider | United States | Standard contractual clauses | Recipient email address and notification content |
A customer may choose to receive alerts on a channel it selects and administers itself: a team messaging tool, a webhook to its SIEM, or an email address. These recipients are not Stealed sub-processors: the customer is responsible for them and determines their configuration and location alone.
Any addition or replacement of a sub-processor is published on this page. Customers under contract are informed in accordance with their data processing agreement and may object under the conditions set out therein.
For any question about this list: [email protected].