Last updated 25 August 2026
Subprocessor & Service Provider Register
Current LumicSec operating policy. Mandatory rights under applicable law continue to apply, and any enterprise or jurisdiction-specific commitment must be expressly agreed in writing.
1. How to read this register
This register identifies the current core third-party service-provider categories used by LumicSec. Whether a provider is legally a subprocessor, independent controller or another type of recipient can depend on the data, customer relationship and applicable law; this page does not silently assign a legal role beyond what the service actually uses.
2. Google-based authentication
Google-based authentication may process account identity and sign-in information needed when a customer chooses the supported Google authentication flow. LumicSec does not use this provider as a destination for raw Scan Access bearer secrets.
3. Vercel application infrastructure
Vercel provides application hosting, deployment, server-side compute, delivery and related operational infrastructure for the LumicSec web application. Technical request and runtime metadata can be processed as necessary to operate and protect the hosted service.
4. Supabase authentication, database and storage
Supabase provides core authentication, database, storage and server-side function infrastructure used for customer accounts, websites, scans, reports, remediation state, billing records and other product data. LumicSec applies product authorization and database controls on top of those services; the provider's own infrastructure terms also apply to its processing.
5. Provider locations and transfers
Core providers can process data in locations where their services operate. LumicSec does not promise a specific data-localization region or international-transfer mechanism through this public register. Customers that require a particular region, transfer mechanism or data-residency commitment should obtain a written enterprise agreement before relying on that requirement.
6. Provider changes and enterprise notice
LumicSec may replace or add providers as the service evolves. Material provider changes that introduce a materially different customer-data use should be reflected in this register or the applicable privacy/data-processing notice. A fixed advance-notice period, objection right or dedicated subprocessor-notification SLA applies only when it is expressly provided in a written agreement.