HexaSentra← Home

Sub-processors

Last updated: 17 September 2026

Our Data Processing Addendum commits us to maintaining a current list of the third parties that process data on your behalf, and to giving notice before that list changes. This is that list.

1. Service infrastructure

These providers are involved in running HexaSentra itself and may process your account data.

ProviderPurposeData it can processLocation
DigitalOceanApplication servers and the primary databaseAll account and scan data at restIndia (Bangalore)
VercelHosting for this marketing websiteRequest logs and IP addresses of site visitors only — no account or scan dataGlobal edge
RazorpayPayment processingBilling contact and payment details. Card details go directly to Razorpay; we never receive or store themIndia
ResendTransactional email (password resets, invitations, alerts)Recipient email address and message contentUnited States
HostingerInbound email for our published addressesAnything you choose to send us by emailEU / Global

2. Data sources queried during a scan

Attack-surface discovery works partly by querying public records. When it does, the hostname you authorized us to scan is sent to the source below. No account details, credentials, or findings are ever shared with them.

SourceWhat it isWhat it receives
crt.shCertificate Transparency log searchYour domain name
Cert Spotter (SSLMate)Certificate Transparency monitoringYour domain name
subdomain.centerPassive subdomain datasetYour domain name
HackerTargetPassive reverse-IP and DNS dataYour domain name or IP
RDAP registriesDomain registration recordsYour domain name
Google Public DNSDNS resolution during discoveryHostnames being resolved

3. Reference feeds (no customer data)

We download vulnerability intelligence in bulk and match it locally. These providers receive nothing about you — not even your domain.

4. Only if you enable them

These are off by default and involve a third party only because you connected it:

5. No AI or LLM provider

The AI Security Analyst runs entirely on our own infrastructure against your stored data. No customer data — no findings, assets, hostnames, or evidence — is sent to any external AI or large-language-model provider. There is no OpenAI, Anthropic, Google, or similar provider in the processing chain.

6. Typography

This website loads its typefaces from Google Fonts, which means Google receives the IP address of visitors to these pages. No cookies are set and no account data is involved. See our Cookie Policy.

7. Changes to this list

We give notice before adding a sub-processor that would process customer data, and you may raise a reasonable objection as described in the DPA. To be notified of changes, email privacy@hexasentra.com.