Legal

Sub-processors

The categories of third-party providers TrustFix uses to deliver the service, and how we notify customers when this list changes.

Pending legal counsel review. This document is a working draft provided for transparency. It has not yet been reviewed by qualified legal counsel and is not yet a binding agreement. Do not rely on it as legal advice. The definitive, executed version will be made available before it takes effect.

Last updated: June 25, 2026

1. About this page

Vikavi Security LLC, operating as TrustFix ("TrustFix", "we"), engages a small number of third-party providers ("sub-processors") to help deliver, secure, and support the Service. A sub-processor is a third party that may process personal data on our behalf under our instructions.

This page describes the categories of sub-processors we use and the purpose each serves. It supplements our Data Processing Addendum (DPA), which governs how personal data is processed on behalf of customers.

2. Categories of sub-processors

We engage sub-processors in the following categories. Within each category we choose established providers and impose contractual data-protection obligations on them that are no less protective than those in our DPA.

  • Cloud hosting and infrastructure: hosts the TrustFix application, databases, and storage. This is where the Service runs and where customer configuration metadata, findings, attestations, and the audit ledger are stored.
  • Transactional email (Resend): sends operational and security email such as sign-in verification, finding alerts, and account notifications. We do not use this for advertising email.
  • Payment processing (Stripe): processes subscription payments. Payment-card details are handled by the processor; TrustFix does not store full card numbers on its own servers.
  • AI model inference: generates remediation recommendations from finding context. Only the metadata needed to produce a fix recommendation is sent; we do not send application source code.
  • Operational tooling: error monitoring, logging, and product analytics used to keep the Service reliable and secure. These process limited operational and usage data.

3. What we do not do

We do not engage advertising networks, data brokers, or cross-site tracking vendors as sub-processors, and we do not sell personal data. We send the minimum data necessary to each provider for its specific purpose, consistent with the principle of data minimization.

4. International processing

Some sub-processors may process data in the United States or other jurisdictions. Where personal data subject to the GDPR or UK GDPR is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses, as described in our DPA.

5. Changes to this list

This list of sub-processor categories may change as the Service evolves. We will update this page and revise the "Last updated" date when we make changes.

Before a new sub-processor begins processing customer personal data, we will provide a mechanism for customers to be notified and to reasonably object, as set out in our DPA. To request advance notice of changes, contact security@trustfix.dev.

6. Contact

Vikavi Security LLC (operating as TrustFix), a Delaware limited liability company, headquartered in the Greater St. Louis area, United States. For questions about our sub-processors, contact security@trustfix.dev. For general inquiries, contact hello@trustfix.dev.

Sub-processors | TrustFix