Short page, because the answer is short. No third party touches your engagement data.
Cetonix engages no sub-processors that access client engagement data. Penetration testing, secure code review, dynamic testing and reporting are delivered entirely by Cetonix personnel on our own payroll, on infrastructure we control.
| Purpose | Sub-processor | Accesses engagement data? |
|---|---|---|
| Security testing delivery | None — in-house employees only | — |
| Report writing and review | None — in-house employees only | — |
| Evidence storage | None — Cetonix-controlled infrastructure | — |
| AI / machine learning services | None — see AI policy below | No |
| Corporate email and website hosting | Standard commercial providers, named on request | No — engagement data is never transmitted or stored through these |
Most testing firms of our size subcontract capacity, particularly on mobile and on large API surfaces. We do not. Every tester assigned to your engagement is a Cetonix employee, bound by an individual confidentiality undertaking in addition to the company NDA, working on an isolated per-engagement environment.
This is the reason we can answer the sub-processor question on one page instead of with a spreadsheet, and the reason a flow-down clause in your DPA costs us nothing to accept.
No client data is submitted to any AI service. Not source code, not configuration, not traffic captures, not credentials, not findings, not report content. Where AI tooling is used for internal work unrelated to client engagements, it is on enterprise tiers with model training disabled and zero data retention.
We accept this as a contractual term, including a flow-down provision, in any client DPA or MSA. Because there are no sub-processors on the delivery side, the flow-down obligation has nothing to flow down to.
Where Cetonix coordinates management system certification, the accredited conformity assessment body that performs your audit is an independent controller of the audit records it creates. It is not a Cetonix sub-processor, and its own data protection terms apply to that processing. We identify the proposed CAB in writing before you commit so you can review its position directly.
If we ever intend to engage a sub-processor with access to engagement data, affected clients receive at least 30 days’ written notice before it is appointed, with the right to object on reasonable data protection grounds and to terminate the affected services without penalty if the objection cannot be resolved.
To be notified of changes, email privacy@cetonix.com and ask to be added to the sub-processor notification list.
Version 1.0 · Last updated: 1 October 2025 · Related: Data Processing Agreement · Security practices · Trust centre