← Trust Center
Register

Sub-Processor List

The third-party sub-processors SafeToOpen uses to deliver its services, what each processes, where, and under which safeguards.

Classification: Public · Version: 1.0 — July 2026 · URL: safetoopen.com/en/trust/sub-processors (referenced from the DPA)

SafeToOpen Ltd uses the following third-party sub-processors to deliver its services. Each is assessed before onboarding and bound by data protection terms consistent with our DPA.

Sub-processorPurposeData processedLocation of processingSafeguards
SiteHost New Zealand LtdCloud hosting of SafeToOpen detection services and stored dataSubmitted page data, verdicts, account dataNew ZealandData processing terms; NZ Privacy Act 2020; ISO 27001-aligned hosting controls

Before publication, add any other vendor that stores or processes customer data — typically: payment provider (e.g., Stripe/Paddle — card data is held by the provider, not SafeToOpen), transactional email service, support/helpdesk tooling, and any breach-database service used for the email checkup feature. Completeness matters: reviewers cross-check this list against the extension's actual network traffic, and an undisclosed processor discovered that way undermines the whole trust pack. If a vendor only ever sees data that never includes customer data, it does not belong on this list.

Change notification

We update this page when sub-processors change and notify customers by email at least 30 days before a new sub-processor processes customer data, giving customers the opportunity to object as set out in the DPA.

Last updated: July 2026 · Review cadence: quarterly

Questions from your security team?

We answer reviewer questions directly and provide the full security review pack under NDA — typical turnaround one business day.

Contact [email protected]