Secure Domains

Sub-processors

DNS Armor™ by Secure Domains

Effective Date27 July 2026
Last Updated28 July 2026
Document Version1.0
ClassificationPublic

To deliver DNS Armor™ we engage a small number of providers — our “Sub-processors” — who process data on our behalf. This is the current list referred to in Annex D of our Data Processing Addendum.

Both DNS Armor™ Protect and DNS Armor™ Resolve are delivered from cloud regions operated by Microsoft Azure and/or Huawei Cloud, depending on the region serving your account.

Each Sub-processor is engaged under a written data-processing contract that meets the requirements of applicable data protection law, is limited to the activity described below, and is reviewed when we engage them and when their terms change. We remain responsible to you for their performance.

How your DNS logs are held

Sub-processors provide infrastructure and delivery; they do not administer your tenant or your policies.

  • Isolated per tenant. Each tenant’s logs are written to storage logically isolated to that tenant alone, addressed only by credentials scoped to it. Tenant scoping is enforced at the storage and application layers so that one customer’s administrators cannot address another customer’s logs.
  • Held in your region. Logs are processed and archived in the service region assigned to, or selected by, your account. Where our authorized personnel need remote access from another country to operate or support the Service, that access is governed by the safeguards set out in our Privacy Policy and Data Processing Addendum.
  • Encrypted in transit and at rest. Query traffic reaches the platform over an encrypted channel pinned to the correct DNS Security Platform instance; archived logs are encrypted at rest.
  • Least-privilege access. Access to log storage is limited to the Service components that require it, and storage credentials are issued per tenant container rather than as a single estate-wide credential.
  • Never correlated across customers. We do not combine or profile one customer’s DNS activity against another’s, and we do not sell or share DNS query data with advertisers or data brokers.
  • No application-level access. Cloud Sub-processors provide storage and compute only. They are not issued portal accounts and have no application-level access to your tenant, your policies or your administrators.

Current Sub-processors

  • Microsoft Azure

    Processing activity
    Cloud infrastructure and object storage hosting the DNS Security Platform, the administration portal and DNS query log archival.
    Data processed
    DNS query logs, device and tenant records and portal account data, stored as encrypted objects.
    Country of establishment
    Microsoft Corporation, United States, contracting through regional affiliates.
  • Huawei Cloud

    Processing activity
    Cloud infrastructure and object storage for deployments served from Huawei Cloud regions.
    Data processed
    DNS query logs and platform data, stored as encrypted objects.
    Country of establishment
    Huawei Technologies Co., Ltd., China, contracting through regional affiliates.
  • Stripe

    Processing activity
    Payment processing, subscription billing and invoicing for self-signup accounts.
    Data processed
    Billing name and email address, subscription and invoice records, and card details entered directly with Stripe. Card numbers are never stored on our systems. No DNS query data is shared.
    Country of establishment
    Stripe, Inc., United States, and Stripe Payments Europe, Limited, Ireland.
  • Brevo

    Processing activity
    Delivery of transactional email — account, security, billing and service notifications.
    Data processed
    Recipient name and email address and the content of the notification sent. No DNS query data is shared.
    Country of establishment
    Brevo SAS, France.

Other service providers (not Sub-processors)

The following providers support the Service but receive no customer, DNS query or personal data, and are therefore not Sub-processors. They are listed for transparency.

  • Threat-intelligence providers

    Processing activity
    Licensed feeds of malicious and high-risk domain intelligence used by the policy engine.
    Data processed
    No Personal Data. These feeds are downloaded into the platform; we do not send customer data, DNS query content or personal information to these providers. Individual licensors are named on request, subject to the confidentiality terms of the relevant licence.
    Country of establishment
    Various; disclosed on request.

Changes to this list

We give customers advance notice, through the administration portal or by email, before a Sub-processor is added or replaced, so that a customer may object. Where a Sub-processor must be added or replaced at shorter notice to maintain the security, legality or continuity of the Service, we will give notice as soon as reasonably practicable. This page is updated whenever the list changes; the “Last Updated” date above reflects the most recent revision. If you object to a change on reasonable data-protection grounds, we will discuss the objection with you in good faith. If we are unable to make an alternative arrangement available within a reasonable period, you may terminate the affected Service on written notice.

To join the notification list, or to ask which service region and contracting entity apply to your account, contact privacy@secure-domains.org.