Authorized Sub-Processors
Vetted third-party infrastructure and service providers engaged by BHISHMASEC CYBERSECURITY SOLUTIONS (OPC) PRIVATE LIMITED.
1. Due Diligence & Selection Criteria
To support the delivery of our security architecture, DevSecOps pipelines, offensive penetration testing, and compliance consulting, BHISHMASEC CYBERSECURITY SOLUTIONS (OPC) PRIVATE LIMITED engages specialized third-party infrastructure providers ("Sub-Processors"). Prior to engagement, each sub-processor undergoes a vendor security risk review verifying SOC 2 Type II or ISO 27001 certification, data residency compliance, and execution of bilateral Data Processing Addenda (DPAs).
2. Authorized Infrastructure Sub-Processors
| Sub-Processor | Service Nature | Location / Region | Data Processed |
|---|---|---|---|
| Amazon Web Services (AWS) | Encrypted cloud hosting, isolated ephemeral testing VPCs, and automated scanner orchestration | Asia-Pacific (Mumbai, India) / Global | Rest-encrypted engagement telemetry & isolated VPC staging data |
| Google LLC (Google Workspace) | Corporate email communication, enterprise calendar scheduling, and CDN typography delivery | United States / Global Cloud | Client inquiry correspondence and business contact details |
| Cloudflare, Inc. / Netlify Inc. | DNS management, DDoS mitigation, and global CDN edge caching | Global Edge Network | Public web traffic routing and encrypted form transport |
3. Sub-Processor Change Notification
BhishmaSec maintains an active notification list for enterprise clients with executed DPAs. Clients will be notified at least thirty (30) days prior to the onboarding of any new sub-processor that will process client confidential data, allowing reasonable opportunity to review and object on valid data protection grounds.
4. Inquiries
For questions or objections regarding our sub-processor directory, email: [email protected]