Authorized Sub-Processors
Vetted third-party infrastructure and service providers authorized to process data on behalf of BhishmaSec.
1. Due Diligence & Selection Criteria
To support the delivery of our security architecture, DevSecOps pipelines, offensive penetration testing, and compliance consulting, BHISHMASEC CYBERSECURITY SOLUTIONS (OPC) PRIVATE LIMITED engages specialized third-party infrastructure providers ("Sub-Processors"). Prior to engagement, each sub-processor undergoes a vendor security risk review verifying SOC 2 Type II or ISO 27001 certification, data residency compliance, and execution of bilateral Data Processing Addenda (DPAs).
2. Authorized Infrastructure Sub-Processors
| Sub-Processor | Service Nature | Location / Region | Data Processed |
|---|---|---|---|
| Amazon Web Services (AWS) | Encrypted cloud hosting, isolated ephemeral testing VPCs, and automated scanner orchestration | Asia-Pacific (Mumbai, India) / Global | Rest-encrypted engagement telemetry & isolated VPC staging data |
| Google LLC (Google Workspace & Public DNS) | Corporate email communication, enterprise calendar scheduling (Google Meet video conferencing), CDN typography delivery, and Google Public DNS API (dns.google) used during passive security reconnaissance for MX, SPF, and DMARC record resolution | United States / Global Cloud | Client inquiry correspondence, business contact details, and security scan target domain names (no personal data) submitted as DNS lookup queries to the public DNS resolver |
| Cal.com, Inc. | Meeting scheduling and calendar booking platform — used to allow inbound prospects and clients to book discovery calls directly with BhishmaSec | United States (Delaware) | Booking requestor full name, business email address, meeting timestamp, and Google Meet video link. Data is also forwarded via Cal.com webhook to BhishmaSec's internal CRM (Clarify) immediately upon booking creation. |
| Cloudflare, Inc. / Netlify Inc. | DNS management, DDoS mitigation, and global CDN edge caching | Global Edge Network | Public web traffic routing and encrypted form transport |
| Apollo.io, Inc. | B2B lead intelligence and prospect data enrichment for outbound security research outreach | United States | Prospect professional contact details (name, business email, job title, company domain) sourced from Apollo public index |
| Instantly Labs, Inc. (Instantly.ai) | Automated cold email outreach and campaign delivery on behalf of BhishmaSec | United States | Prospect name, business email address, company name, and personalised email content generated from passive security scan findings |
| Clarify CRM (clarify.ai) | Customer relationship management — stores and tracks prospect and inbound lead interactions | United States | Prospect and inbound contact name, business email, company domain, job title, and interaction notes |
| GitHub, Inc. (Microsoft) | Source code version control, CI/CD pipeline execution, and internal infrastructure configuration management | United States / Global | Internal Lambda source code, infrastructure configuration files, and CI/CD workflow logs. No client data stored. |
| Sectigo Limited (crt.sh) | Certificate Transparency log aggregator — queried during passive security reconnaissance to enumerate publicly registered subdomains | United Kingdom / Global | Target company domain names submitted as read-only lookup queries to the public CT log index. No personal data transmitted. |
3. Sub-Processor Change Notification
BhishmaSec maintains an active notification list for enterprise clients with executed DPAs. Clients will be notified at least thirty (30) days prior to the onboarding of any new sub-processor that will process client confidential data, allowing reasonable opportunity to review and object on valid data protection grounds.
4. Inquiries
For questions or objections regarding our sub-processor directory, email: [email protected]