← Back to S-Core Compliance

Data Processing Agreement

S-Core Analytics Inc. · Effective date: August 11, 2026 · Version 1.0

This DPA is incorporated by reference into, and takes effect automatically alongside, our Terms of Service the moment you create an account or otherwise use S-Core Compliance to process personal data. No separate signature is required for it to apply. If your organization needs a countersigned copy for your own vendor records, email hello@s-coreanalytics.com and we'll return one, typically within 2 business days.

1. Parties and roles

This Data Processing Agreement ("DPA") is between the customer entity that has agreed to our Terms of Service ("Customer", "Controller") and S-Core Analytics Inc. ("S-Core", "Processor"). Where Customer processes personal data of its own end users or employees through S-Core Compliance (the "Service"), Customer acts as Controller (or, where applicable, Processor on behalf of its own customers) and S-Core acts as Processor (or Sub-processor) with respect to that personal data.

2. Subject matter and duration

S-Core processes personal data on Customer's behalf solely to provide the Service: continuous configuration monitoring of systems Customer connects, policy generation, attestation and training tracking, personnel/vendor records Customer enters, and compliance reporting. This DPA applies for as long as S-Core processes personal data on Customer's behalf under the Terms of Service, and survives termination for as long as S-Core retains any such data.

3. Nature and purpose of processing

Hosting, storage, and automated processing of the categories of data below, strictly to operate the features Customer has enabled - running the scheduled and on-demand checks Customer configures, generating documents and reports, and sending the transactional/alert emails Customer's configuration triggers. S-Core does not process personal data for any other purpose, and does not use it to train machine-learning models.

Categories of data subjects

Categories of personal data

S-Core does not intentionally collect special categories of data (Art. 9 GDPR) and asks Customer not to enter such data into free-text fields (e.g., risk register notes, vendor notes).

4. Processor obligations

5. Sub-processors

Customer provides general authorization for S-Core to engage the sub-processors below to provide the Service. S-Core will post updates to this list here and, for material additions, notify account holders by email with an opportunity to object before the new sub-processor begins processing Customer's personal data.

Sub-processorPurposeLocation
Google Cloud Platform / FirebaseHosting, database (Firestore), authenticationUnited States
Stripe, Inc.Subscription billing and payment processingUnited States
ResendTransactional email delivery (alerts, reports, invitations)United States
Anthropic, PBCAI Copilot, AI-drafted remediation guidance, and AI-drafted vendor-questionnaire answers (only when Customer actively uses these features)United States

Systems Customer itself connects to the Service (GitHub, AWS, Google Cloud, Microsoft Azure, Vercel, Okta, Google Workspace, or a customer-supplied external-scan target) are Customer's own systems, accessed strictly per Customer's instruction and credentials - S-Core does not consider these its sub-processors.

6. Security measures

Summary of the technical and organizational measures S-Core maintains, consistent with Art. 32 GDPR:

7. International data transfers

Personal data is processed and stored in the United States. Where Customer is located in the European Economic Area, United Kingdom, or Switzerland, the transfer is governed by the Standard Contractual Clauses (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor as applicable), incorporated into this DPA by reference, available on request.

8. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service.

9. Precedence and governing law

In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA governs. This DPA is governed by the laws of the State of New Jersey, USA, except where Data Protection Laws require otherwise for the personal data in question.

10. Contact

Data Protection contact: S-Core Analytics Inc. · New Jersey, USA · hello@s-coreanalytics.com