Data Processing Agreement
1. Parties and roles
This Data Processing Agreement ("DPA") is between the customer entity that has agreed to our Terms of Service ("Customer", "Controller") and S-Core Analytics Inc. ("S-Core", "Processor"). Where Customer processes personal data of its own end users or employees through S-Core Compliance (the "Service"), Customer acts as Controller (or, where applicable, Processor on behalf of its own customers) and S-Core acts as Processor (or Sub-processor) with respect to that personal data.
2. Subject matter and duration
S-Core processes personal data on Customer's behalf solely to provide the Service: continuous configuration monitoring of systems Customer connects, policy generation, attestation and training tracking, personnel/vendor records Customer enters, and compliance reporting. This DPA applies for as long as S-Core processes personal data on Customer's behalf under the Terms of Service, and survives termination for as long as S-Core retains any such data.
3. Nature and purpose of processing
Hosting, storage, and automated processing of the categories of data below, strictly to operate the features Customer has enabled - running the scheduled and on-demand checks Customer configures, generating documents and reports, and sending the transactional/alert emails Customer's configuration triggers. S-Core does not process personal data for any other purpose, and does not use it to train machine-learning models.
Categories of data subjects
- Customer's own workspace users (account owner, invited team members, sub-account holders)
- Customer's personnel recorded in the Personnel/Training modules (name, email, training/background-check/device status)
- Individuals identifiable in connected-system scan output (e.g., a GitHub username or IAM user email that appears in a finding)
Categories of personal data
- Contact data: name, work email, role
- Account/authentication data: managed through Firebase Authentication
- Employment-adjacent records Customer voluntarily enters: training completion, background-check status, device/MDM enrollment
- Technical identifiers appearing in integration scan results (usernames, IAM principals, IP addresses in logs)
S-Core does not intentionally collect special categories of data (Art. 9 GDPR) and asks Customer not to enter such data into free-text fields (e.g., risk register notes, vendor notes).
4. Processor obligations
- Instructions. S-Core processes personal data only on Customer's documented instructions (including those given through Customer's own configuration of the Service), unless required otherwise by law, in which case S-Core will inform Customer before processing unless legally prohibited from doing so.
- Confidentiality. S-Core ensures personnel authorized to process personal data are bound by confidentiality obligations.
- Security (Art. 32). S-Core implements and maintains the technical and organizational measures described in Section 6.
- Sub-processor authorization. S-Core will not engage a new sub-processor to process personal data without giving Customer the opportunity to object (Section 5).
- Assistance. S-Core assists Customer, using appropriate technical and organizational measures, in fulfilling data subject rights requests and in complying with Art. 32-36 GDPR obligations (security, breach notification, DPIAs), to the extent consistent with the information S-Core has available.
- Breach notification. S-Core notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer's data.
- Deletion or return. At the end of the provision of Services, S-Core deletes or returns all personal data at Customer's choice, unless retention is required by law. Customer can trigger this directly: Settings → Danger Zone → Delete Workspace performs an immediate, permanent recursive delete of the workspace record and everything nested under it (evidence, activity log, stored integration credentials).
- Audit. S-Core makes available information reasonably necessary to demonstrate compliance with this DPA and allows for, and contributes to, audits (including inspections) conducted by Customer or an auditor mandated by Customer, subject to reasonable notice, confidentiality, and no more than once per 12-month period absent cause.
5. Sub-processors
Customer provides general authorization for S-Core to engage the sub-processors below to provide the Service. S-Core will post updates to this list here and, for material additions, notify account holders by email with an opportunity to object before the new sub-processor begins processing Customer's personal data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform / Firebase | Hosting, database (Firestore), authentication | United States |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| Resend | Transactional email delivery (alerts, reports, invitations) | United States |
| Anthropic, PBC | AI Copilot, AI-drafted remediation guidance, and AI-drafted vendor-questionnaire answers (only when Customer actively uses these features) | United States |
Systems Customer itself connects to the Service (GitHub, AWS, Google Cloud, Microsoft Azure, Vercel, Okta, Google Workspace, or a customer-supplied external-scan target) are Customer's own systems, accessed strictly per Customer's instruction and credentials - S-Core does not consider these its sub-processors.
6. Security measures
Summary of the technical and organizational measures S-Core maintains, consistent with Art. 32 GDPR:
- Encryption in transit (TLS) for all connections to the Service; encryption at rest via Google Cloud's default infrastructure encryption
- Per-tenant data isolation enforced at the application layer (verified by automated tests) - a signed-in user can only ever read or write their own workspace, never another organization's
- Least-privilege, read-only credentials requested for every connected integration; credentials are stored server-side only and never returned to the browser
- Role-based access within a workspace (Owner, Admin, Auditor, Viewer)
- Automated daily backups of the primary datastore (7-day retention)
- Rate limiting and per-account abuse caps on state-changing and AI-backed endpoints
- A documented, timestamped activity log of security-relevant actions within each workspace
- Content-Security-Policy and other standard HTTP security headers on the application
7. International data transfers
Personal data is processed and stored in the United States. Where Customer is located in the European Economic Area, United Kingdom, or Switzerland, the transfer is governed by the Standard Contractual Clauses (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor as applicable), incorporated into this DPA by reference, available on request.
8. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service.
9. Precedence and governing law
In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA governs. This DPA is governed by the laws of the State of New Jersey, USA, except where Data Protection Laws require otherwise for the personal data in question.
10. Contact
Data Protection contact: S-Core Analytics Inc. · New Jersey, USA · hello@s-coreanalytics.com