info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeSub-processors

Sub-processors

Short page, because the answer is short. No third party touches your engagement data.

Cetonix engages no sub-processors that access client engagement data. Penetration testing, secure code review, dynamic testing and reporting are delivered entirely by Cetonix personnel on our own payroll, on infrastructure we control.

Current sub-processor list

Purpose Sub-processor Accesses engagement data?
Security testing deliveryNone — in-house employees only
Report writing and reviewNone — in-house employees only
Evidence storageNone — Cetonix-controlled infrastructure
AI / machine learning servicesNone — see AI policy belowNo
Corporate email and website hostingStandard commercial providers, named on requestNo — engagement data is never transmitted or stored through these

Why the list is empty where it matters

Most testing firms of our size subcontract capacity, particularly on mobile and on large API surfaces. We do not. Every tester assigned to your engagement is a Cetonix employee, bound by an individual confidentiality undertaking in addition to the company NDA, working on an isolated per-engagement environment.

This is the reason we can answer the sub-processor question on one page instead of with a spreadsheet, and the reason a flow-down clause in your DPA costs us nothing to accept.

Artificial intelligence and machine learning services

No client data is submitted to any AI service. Not source code, not configuration, not traffic captures, not credentials, not findings, not report content. Where AI tooling is used for internal work unrelated to client engagements, it is on enterprise tiers with model training disabled and zero data retention.

We accept this as a contractual term, including a flow-down provision, in any client DPA or MSA. Because there are no sub-processors on the delivery side, the flow-down obligation has nothing to flow down to.

Certification coordination

Where Cetonix coordinates management system certification, the accredited conformity assessment body that performs your audit is an independent controller of the audit records it creates. It is not a Cetonix sub-processor, and its own data protection terms apply to that processing. We identify the proposed CAB in writing before you commit so you can review its position directly.

Changes to this list

If we ever intend to engage a sub-processor with access to engagement data, affected clients receive at least 30 days’ written notice before it is appointed, with the right to object on reasonable data protection grounds and to terminate the affected services without penalty if the objection cannot be resolved.

To be notified of changes, email privacy@cetonix.com and ask to be added to the sub-processor notification list.

Version 1.0 · Last updated: 1 October 2025 · Related: Data Processing Agreement · Security practices · Trust centre