Sub-processors
DNS Armor™ by Secure Domains
To deliver DNS Armor™ we engage a small number of providers — our “Sub-processors” — who process data on our behalf. This is the current list referred to in Annex D of our Data Processing Addendum.
Both DNS Armor™ Protect and DNS Armor™ Resolve are delivered from cloud regions operated by Microsoft Azure and/or Huawei Cloud, depending on the region serving your account.
Each Sub-processor is engaged under a written data-processing contract that meets the requirements of applicable data protection law, is limited to the activity described below, and is reviewed when we engage them and when their terms change. We remain responsible to you for their performance.
How your DNS logs are held
Sub-processors provide infrastructure and delivery; they do not administer your tenant or your policies.
- Isolated per tenant. Each tenant’s logs are written to storage logically isolated to that tenant alone, addressed only by credentials scoped to it. Tenant scoping is enforced at the storage and application layers so that one customer’s administrators cannot address another customer’s logs.
- Held in your region. Logs are processed and archived in the service region assigned to, or selected by, your account. Where our authorized personnel need remote access from another country to operate or support the Service, that access is governed by the safeguards set out in our Privacy Policy and Data Processing Addendum.
- Encrypted in transit and at rest. Query traffic reaches the platform over an encrypted channel pinned to the correct DNS Security Platform instance; archived logs are encrypted at rest.
- Least-privilege access. Access to log storage is limited to the Service components that require it, and storage credentials are issued per tenant container rather than as a single estate-wide credential.
- Never correlated across customers. We do not combine or profile one customer’s DNS activity against another’s, and we do not sell or share DNS query data with advertisers or data brokers.
- No application-level access. Cloud Sub-processors provide storage and compute only. They are not issued portal accounts and have no application-level access to your tenant, your policies or your administrators.
Current Sub-processors
Microsoft Azure
- Processing activity
- Cloud infrastructure and object storage hosting the DNS Security Platform, the administration portal and DNS query log archival.
- Data processed
- DNS query logs, device and tenant records and portal account data, stored as encrypted objects.
- Country of establishment
- Microsoft Corporation, United States, contracting through regional affiliates.
Huawei Cloud
- Processing activity
- Cloud infrastructure and object storage for deployments served from Huawei Cloud regions.
- Data processed
- DNS query logs and platform data, stored as encrypted objects.
- Country of establishment
- Huawei Technologies Co., Ltd., China, contracting through regional affiliates.
Stripe
- Processing activity
- Payment processing, subscription billing and invoicing for self-signup accounts.
- Data processed
- Billing name and email address, subscription and invoice records, and card details entered directly with Stripe. Card numbers are never stored on our systems. No DNS query data is shared.
- Country of establishment
- Stripe, Inc., United States, and Stripe Payments Europe, Limited, Ireland.
Brevo
- Processing activity
- Delivery of transactional email — account, security, billing and service notifications.
- Data processed
- Recipient name and email address and the content of the notification sent. No DNS query data is shared.
- Country of establishment
- Brevo SAS, France.
Other service providers (not Sub-processors)
The following providers support the Service but receive no customer, DNS query or personal data, and are therefore not Sub-processors. They are listed for transparency.
Threat-intelligence providers
- Processing activity
- Licensed feeds of malicious and high-risk domain intelligence used by the policy engine.
- Data processed
- No Personal Data. These feeds are downloaded into the platform; we do not send customer data, DNS query content or personal information to these providers. Individual licensors are named on request, subject to the confidentiality terms of the relevant licence.
- Country of establishment
- Various; disclosed on request.
Changes to this list
We give customers advance notice, through the administration portal or by email, before a Sub-processor is added or replaced, so that a customer may object. Where a Sub-processor must be added or replaced at shorter notice to maintain the security, legality or continuity of the Service, we will give notice as soon as reasonably practicable. This page is updated whenever the list changes; the “Last Updated” date above reflects the most recent revision. If you object to a change on reasonable data-protection grounds, we will discuss the objection with you in good faith. If we are unable to make an alternative arrangement available within a reasonable period, you may terminate the affected Service on written notice.
To join the notification list, or to ask which service region and contracting entity apply to your account, contact privacy@secure-domains.org.
