UK GDPR / DPA 2018
Full compliance. Standard DPA available pre-contract.
We sell to CISOs. Our own security posture is the first thing they assess. Below is the same architecture, sub-processor and compliance roadmap document we hand over during procurement — but public.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase Inc. | Managed database hot store and authentication | UK / EU |
| Amazon Web Services | Long-term encrypted cold archive | eu-west-2 (London) |
| Vercel Inc. | Edge CDN and serverless function runtime | UK edge presence |
| FreeTSA / Sectigo TSA | RFC 3161 timestamping (optional) | EU |
| Stripe | Billing | UK / EU |
Any change to this list is notified at least 30 days in advance per our standard DPA, and customers may object in writing.
Full compliance. Standard DPA available pre-contract.
Article 28 sub-processor terms, SCC + UK IDTA available for international transfers.
Targeted for 2027 once first paid customers are live. We will publish the engaged auditor and audit window when booked.
Targeted alongside SOC 2 in 2027. ISMS scope drafted; we will publish the certification body and audit dates when engaged.
Targeted via the VantagePoint Networks parent organisation.
For UK healthcare customers. Submission targeted Q4 2026.
We take coordinated disclosure seriously. Email info@vpnetworks.co.uk with details of any suspected vulnerability. We acknowledge within one working day and aim for a coordinated disclosure within 90 days.
For the curious, our /.well-known/security.txt is the machine-readable canonical version.