Trust Center · Vendors

Subprocessors

Every third party that may process Lockzero customer data, including the data they access, where they’re hosted, and what compliance certifications they hold. We notify customers before adding a new subprocessor.

Last updated: 2026-05-02 · For DPA execution, email security@lockzero.io

VendorPurposeData accessedRegionCertificationsRisk tier
Amazon Web Services (AWS)Compute (EC2), database hosting (RDS Postgres), object storage (S3), key management (KMS), secrets storage (Secrets Manager), email delivery (SES), monitoring (CloudWatch), DNS health checksAll customer data — encrypted at rest with AES-256-GCM, keys managed in AWS KMSus-east-1 (N. Virginia)SOC 1/2/3ISO 27001/17/18PCI DSS L1HIPAA-eligibleFedRAMP HighC5IRAPCritical
CloudflareEdge network: DNS, DDoS mitigation, Cloudflare Tunnel for origin connectivity, WAF (when on Pro tier)Request metadata (IP, user agent, path) — no customer secrets traverse Cloudflare in plaintext (TLS terminated at origin)Global anycastSOC 2 Type IIISO 27001PCI DSS L1FedRAMP ModerateMedium
ClerkIdentity provider for sign-in / sign-up flows on the lockzero.io web appEmail address, name, sign-in metadata. No secrets, no customer credentials.us-east-1SOC 2 Type IIGDPR-alignedHigh
Auth0 (Okta)OIDC provider for SSO + enterprise authentication pathsUser identity tokens (JWT); Lockzero-side user IDs; auth audit metadataus-east region (configurable to EU)SOC 2 Type IIISO 27001/17/18HIPAA-eligiblePCI DSSHigh
StripePayment processing for paid tiers; subscription billingCustomer billing email + plan info. Card data never touches Lockzero servers — entered directly into Stripe Elements.us-east regionSOC 1/2PCI DSS L1ISO 27001Medium
ResendTransactional email delivery (welcome, password reset, alerts)Email address, message content (no secrets — only audit/system messages)us-east-1 / Cloudflare R2SOC 2 Type IIGDPR-alignedMedium
SentryApplication error monitoringStack traces and request metadata. Configured to scrub PII and never capture secret values.us-east-1SOC 2 Type IIISO 27001GDPR-alignedLow
GitHubSource code hosting, CI (Actions), container registrySource code (private repository); CI logs. No customer data.GlobalSOC 1/2ISO 27001/17/18FedRAMP ModerateGDPR-alignedLow
Risk key:CriticalStores or processes encrypted customer secrets and/or database contentsHighHandles user identity or authentication tokens — compromise enables account takeoverMediumProcesses billing or contact data; no access to secrets or auth tokensLowReceives only operational metadata (logs, code); no customer PII or secrets

← Back to Trust Center

Subprocessors — Lockzero Trust Center | Lockzero