UK GDPR / DPA 2018
Full compliance. Standard DPA available pre-contract.
We sell to CISOs. Our own security posture is the first thing they assess. Below is the same architecture, sub-processor, and compliance roadmap document we provide during procurement — but public.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase Inc. | Postgres hot store, magic-link auth | UK / EU |
| Amazon Web Services | S3 cold storage, Parquet archive | eu-west-2 (London) |
| Vercel Inc. | Edge static, Python serverless API | UK edge presence |
| FreeTSA / Sectigo TSA | RFC 3161 timestamping (optional) | EU |
| Stripe | Billing | UK / EU |
Any change to this list is notified at least 30 days in advance per our standard DPA, and customers may object in writing.
Full compliance. Standard DPA available pre-contract.
Article 28 sub-processor terms, SCC + UK IDTA available for international transfers.
Audit window Q1 2027. Trust Services Criteria scoping complete.
ISMS scoped, gap analysis complete. Stage 1 audit booked Q2 2027.
Certified under VantagePoint Networks parent organisation.
For UK healthcare customers. Submission targeted Q4 2026.
We take coordinated disclosure seriously. Email info@vpnetworks.co.uk with details of any suspected vulnerability. We acknowledge within one working day and aim for a coordinated disclosure within 90 days.
For the curious, our /.well-known/security.txt is the machine-readable canonical version.