LEXSEC | Advisory ← Back to Home

Sub-processors

Last updated: 26 June 2026  ·  LexSec Advisory LLC

LexSec Advisory LLC uses a small number of trusted third-party providers ("sub-processors") to deliver our services. This page lists those sub-processors, the purpose of each, and the data they may process on our behalf. We update this page whenever we add, change, or remove a sub-processor.

Current sub-processors

Sub-processor Purpose Data processed Location
Cloudflare, Inc. Hosting, edge network, application platform (Workers), database (D1), object storage (R2) Account data, GRC content, evidence files, session cookies, server logs United States (global edge)
Resend (Drape, Inc.) Transactional email delivery (account confirmations, invitations, waitlist confirmations) Recipient email address, recipient name, message content United States
Google LLC (Google Workspace) Internal business email and document collaboration for the LexSec Advisory team Inbound and outbound email correspondence with customers, prospects, and partners United States

Sub-processor changes

We will update this page before engaging any new sub-processor that processes customer personal data. Customers who wish to receive advance notice of sub-processor changes by email can subscribe by writing to info@lexsecadvisory.com.

Data protection

Each sub-processor listed above is contractually bound to provide a level of data protection at least equivalent to our own commitments under our Privacy Policy. Where required, we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms for any cross-border data flows.

Customer data (the GRC content you enter into the platform) is processed only by Cloudflare. Resend and Google Workspace do not receive the substantive contents of your risk register, evidence files, controls, or other GRC records.

Contact

Questions about our sub-processors or data processing practices: info@lexsecadvisory.com

© 2026 LexSec Advisory LLC. All rights reserved.