Trust + Sub-Processors
This page is the public-facing summary of how Pzartech Ltd. handles security, the third-party services we use to operate the site and Pzartech products, and how you can raise concerns or request the long-form documentation.
Last reviewed: 2026-05-27. Sub-processor changes are reflected here within 7 days of the change taking effect; material additions are notified to active customers at least 30 days in advance per our standard DPA terms.
Security at a glance
- TLS 1.2+ for all customer-facing traffic; HSTS enabled.
- Public API payloads are bounded and validated before any delivery side effect.
- Contact recovery is encrypted before persistence and expires after 30 days.
- Structured event logging redacts secret and personal-content fields.
- Card details are never collected or stored on this site; payment is handled through Pikood.
- Mandatory two-factor authentication on founder and operator production accounts.
- Cloud-account-level alerting on configuration drift and unexpected privilege changes.
Sub-processors
Pzartech uses the third parties below to deliver the public site and contact workflow. Each receives only the data needed for its role; standard Data Processing Agreements are in place with each provider.
| Provider | Role | Where data is processed | Cross-border safeguard |
|---|---|---|---|
| Cloudflare | Hosting, edge CDN, serverless functions, DNS | Global edge; configurable regional preferences | SCCs + Cloudflare DPA; SOC 2 Type II, ISO 27001/27018/27701 |
| Pikood | Separate payment, billing, invoicing, and entitlement control plane | See Pikood disclosures | Governed by the Pikood service boundary |
| Railway | Optional hosting for the isolated contact relay | Selected deployment region | SCCs + Railway DPA; SOC 2 Type II |
| Supabase | Postgres database, authentication, object storage (per product) | Per-project: EU-Frankfurt for EU-residency, US-East-1 otherwise | SCCs + Supabase DPA; SOC 2 Type II |
| Google Firebase | User authentication and identity for product apps (Snapr SN, others) | EU + US (per Google data location commitments) | EU-US Data Privacy Framework; SCCs; ISO 27001/27017/27018 |
| Google Workspace | Business email + collaboration for Pzartech staff | EU + US (per Google data location commitments) | EU-US Data Privacy Framework; SCCs; ISO 27001/27017/27018 |
| Google Analytics (if enabled) | Aggregate site usage; opt-in only | EU + US | EU-US Data Privacy Framework; analytics_storage default denied until consented |
| Sentry (where used) | Error monitoring on product backends | EU + US (per project SDK configuration) | SCCs + Sentry DPA |
| Anthropic | Claude API for LLM-backed product features (Pikood, aipliance, others) | US (default) or AWS Bedrock regional | SCCs available where cross-border applicable; SOC 2 Type II |
Authoritative internal register: see our governance documentation (available on request to active B2B customers). The application code is built to reject calls to any sub-processor not in this register.
Data location + residency
Product deployment and billing residency depend on the selected product and Pikood configuration. For strict residency requirements, contact us before purchase so we can confirm the deployment topology.
Audit + DPA
Pzartech offers a customer-facing Data Processing Agreement (DPA) for B2B customers processing personal data through Pzartech products. The DPA covers scope, sub-processors, security measures, breach notification, transfers, audit rights, and deletion / return of data on termination. Request the executable version through the contact form or info@pzartech.com.
Security disclosures + responsible disclosure
Security concerns can be reported to info@pzartech.com. We acknowledge reports within 24 hours and target a public-facing remediation status within 30 days from acknowledgment. We do not currently pay a bounty; we credit researchers publicly with consent.
Contact
- Privacy: info@pzartech.com
- Security: info@pzartech.com
- DPA requests: info@pzartech.com
- General: info@pzartech.com