Last updated 25 August 2026

Subprocessor & Service Provider Register

Current LumicSec operating policy. Mandatory rights under applicable law continue to apply, and any enterprise or jurisdiction-specific commitment must be expressly agreed in writing.

1. How to read this register

This register identifies the current core third-party service-provider categories used by LumicSec. Whether a provider is legally a subprocessor, independent controller or another type of recipient can depend on the data, customer relationship and applicable law; this page does not silently assign a legal role beyond what the service actually uses.

2. Google-based authentication

Google-based authentication may process account identity and sign-in information needed when a customer chooses the supported Google authentication flow. LumicSec does not use this provider as a destination for raw Scan Access bearer secrets.

3. Vercel application infrastructure

Vercel provides application hosting, deployment, server-side compute, delivery and related operational infrastructure for the LumicSec web application. Technical request and runtime metadata can be processed as necessary to operate and protect the hosted service.

4. Supabase authentication, database and storage

Supabase provides core authentication, database, storage and server-side function infrastructure used for customer accounts, websites, scans, reports, remediation state, billing records and other product data. LumicSec applies product authorization and database controls on top of those services; the provider's own infrastructure terms also apply to its processing.

5. Provider locations and transfers

Core providers can process data in locations where their services operate. LumicSec does not promise a specific data-localization region or international-transfer mechanism through this public register. Customers that require a particular region, transfer mechanism or data-residency commitment should obtain a written enterprise agreement before relying on that requirement.

6. Provider changes and enterprise notice

LumicSec may replace or add providers as the service evolves. Material provider changes that introduce a materially different customer-data use should be reflected in this register or the applicable privacy/data-processing notice. A fixed advance-notice period, objection right or dedicated subprocessor-notification SLA applies only when it is expressly provided in a written agreement.

LumicSec provides security decision-support information, not a guarantee of complete security or legal compliance. Use the service only with proper authorization.