SoSafe – List of Sub-Processors

Effective April 1, 2026

SoSafe engages the following third-party entities (referred to as “sub-processors”) to process personal data on behalf of its customers. These sub-processors operate under contractual agreements with SoSafe, ensuring adherence to the commitments outlined in the SoSafe Data Processing Agreement.

To maintain compliance, SoSafe conducts annual reviews of its sub-processors and requires them to implement appropriate technical and organisational measures. These measures are designed to safeguard the processing of personal data in accordance with applicable data protection laws.

The list below details the sub-processors supporting SoSafe’s Awareness Building Services.

Sub-processorOptional / Non-optionalAddressPurpose of ProcessingData Storage Location
Amazon Web Services EMEA SARL (Amazon Web Services, Inc. as the contractual party of the EU standard contractual clauses)Non-optional38 Avenue John F. Kennedy L-1855, Luxemburg
Luxemburg
Hosting of all current and future components essential for the operational functionality of the SoSafe Platform, including API interfaces, data storage systems, analytical tools, hosting of (optional) AI chatbots and tooling, and communication capabilities.

The following measures have been taken to protect the data:

– Storage of and, to the extent made available by AWS to its customers for the respective service, processing of all Controller data in certified data centres in the EU. To ensure low latency and high transfer speeds worldwide, we use Amazon CloudFront, AWS’s global content delivery network (CDN). This is a performance/optimization service that may transmit or cache content globally but does not change the primary data storage location.
– Encryption:
All data in transit is encrypted using Transport Layer Security (TLS / HTTPS).
All data at rest is encrypted using 256-bit Advanced Encryption Standard.
– Conclusion of a data processing agreement as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021, module 2 and 3), incl. numerous obligations of AWS on handling and transparency in case of potential authority requests. 
– Amazon Web Services, Inc., is an active participant in the EU-US Data Privacy Framework.
EU
Optional
Amazon Bedrock: Providing interactive awareness and support and other AI-powered tooling, when selected by the Controller.
Atlassian Pty Ltd.Non-optionalLevel 6, 341 George Street, Sydney, NSW 2000
Australia
Provision of support software (Customer Support Cloud Solution) for customer service (support form or email to support@sosafe.de). This provider is only relevant for the Controller if the Controller uses Processor’s customer support or interacts with Processor for other operational purposes related to his contracted Awareness Building Services.

– ISO27001 certificate can be accessed here: https://www.atlassian.com/trust/compliance/resources/iso27001.
– SOC 2 Type II certificate can be accessed here: https://www.atlassian.com/trust/compliance/resources/soc2.
– More information: https://www.atlassian.com/trust and dataprotection@atlassian.com

The following measures have been taken to protect the data:

– Storage and processing of all Controller data in data centres in EU (Ireland, Frankfurt) and, to the extent a EU-only solution is not available by Atlassian (according to Atlassian Statement), in Australia.
– Encryption of all data with industry-standard encryption products during transfers as well as at rest.
– Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021, Modules 2 and 3)
– Transfer Impact Assessment (TIA) conducted by Processor’s external Data Protection Officer.
EU and, to the extent a EU-only solution is not available by Atlassian, Australia.
Planhat ABNon-optionalMalmskillnadsgatan 13, 111 57 Stockholm
Sweden
Provision of customer success management and account management services. This provider is only relevant for the Controller if the Controller uses Processor’s customer support or interacts with Processor for other operational purposes related to his contracted Awareness Building Services.

– SOC 2 certificate can be requested here: compliance@planhat.com.
– More information: https://www.planhat.com/security-statement/

The following measures have been taken to protect the data:

– All data are processed and stored exclusively within the European Union (Ireland). Server hosting provider: Google Cloud EMEA Limited, ISO 27001 certified.  
– Encryption:
— All data in transit is encrypted using Transport Layer Security (TLS / HTTPS).
— Data at rest, provided by Planhat’s customers within the Planhat application is stored using industry-standard AES-256.
– Conclusion of a data processing agreement.
EU
Datadog Inc.Non-optional620 8th Ave., 45th Fl., New York, NY 10018
USA
Provision of technical monitoring service for hybrid cloud applications provided on a SaaS-based data analytics platform.

– ISO/IEC 27017:2015 can be downloaded from here: https://trust.datadoghq.com/?itemUid=1fed9faa-4a87-427c-9a95-96b4d6bf66b7&source=documents_card
– SOC 2 Type I and II certificates can be requested here: security@datadoghq.com.
– More information: https://trust.datadoghq.com/ .

The following measures have been taken:

– All data are processed and stored within the European Union.  
– Encryption:
— Data at rest is encrypted with AES 256.
— All data transmitted between Datadog and Datadog users is protected using Transport Layer Security (TLS) and HTTP Strict Transport Security (HSTS). If encrypted communication is interrupted the Datadog application is inaccessible.
– Conclusion of a data processing agreement as well as conclusion of the EU standard contractual clauses ((EU) 2021/914).
– Datadog, Inc. is active participant in the EU-US Data Privacy Framework.
EU
Functional Software, Inc.
dba “Sentry”,
Non-optional45 Fremont Street, 8th Floor
San Francisco, CA 94105-2250
USA
Product error tracking and performance monitoring

Sentry has obtained the following compliance certifications, that can be requested here  https://sentry.io/contact/enterprise/  
– SOC2 Type I 
– SOC2 Type II
– ISO 27001.
– More information on security and compliance: https://sentry.io/security/.

The following measures have been taken:

– All data are processed and stored within the European Union.  
– Encryption: Data is encrypted at rest. Data transfers are secured using Transport Layer Security (TLS) and industry standard encryption.
– Conclusion of a data processing agreement as well as conclusion of the EU standard contractual clauses ((EU) 2021/914).
– Sentry.io is an active participant in the EU-US Data Privacy Framework.
EU
(Optional) Kombo Technologies GmbHOptionalLohmühlenstraße 65, 12435 Berlin
Germany
Integration of Controller Active Directory. This provider is only required to the extent the Controller requests Active Directory integration for automated uploading and regular updating of end-user data on the Processor platform.
 
The following measures have been taken to protect the data:
 
– All data are processed and stored exclusively within the European Union. Server hosting provider: Google Cloud EMEA Limited.
– Kombo Technologies GmbH is ISO27001 certified. Access can be requested here: https://security.kombo.dev/?itemUid=1fed9faa-4a87-427c-9a95-96b4d6bf66b7&source=click/. More information about Technical and Organizational Security Measures of Kombo Technologies GmbH can be found at security.kombo.dev.
– Encryption
— All customer data is encrypted using symmetric AES-256 encryption at rest, including backup copies.
— Data in transit: All outgoing traffic (to integration APIs) uses the highest TLS version available by the respective integration’s API (e.g., Google Workspace). All incoming traffic via the Kombo API is enforced to use TLS 1.3. Connections from Kombo’s application workloads to Kombo’s database also use TLS 1.3 with an AES-256 cipher.
– Conclusion of a data processing agreement.

EU
(Optional) OpenAI Ireland Ltd. (OpenAI OpCo, LLC as the contractual party of the DPA)Optional1st Floor, The Liffey Trust Centre 117-126 Sheriff Street Upper Dublin 1, D01 YC43
Ireland
Providing interactive awareness and support and other AI-powered tooling, when selected by the Controller.

– SOC 2 and SOC 3 certificates are available upon request: https://trust.openai.com/;
– More information about OpenAI’s technical and organisational security measures are available at https://trust.openai.com/ (the “Trust Portal”).

The following measures have been taken to protect the data:

– Encryption:
— OpenAI maintains industry best practices for encryption which in particular include:
— Encryption of data at rest in production datastores using strong encryption algorithms;
— Encryption of data in transit;
— Full-disk encryption required on all corporate workstations.
– Conclusion of a data processing agreement as well as conclusion of the EU standard contractual clauses.
EU, and, to the extent an EU-only solution is not available, the US.

If you are contracting with another entity than SoSafe SE, SoSafe SE will be a sub-processor, as well.

Further details regarding privacy and security are available on the SoSafe Trust Center.

Important Note: New customers entering into a contract with SoSafe for the provision of Awareness Building Services between 20 August and 19 September 2026 also agree to the following list of sub-processors, which will be implemented as of 20 September 2026.

Sub-processorOptional / Non-optionalPurpose of Processing Measures Taken to Protect Personal Data. Compliance and Security CertificatesData Storage Location
Zendesk, Inc.
181 Fremont St 17th Floor San Francisco, CA 94105 USA
Non-optionalProvision of customer support and ticketing services, including the management, tracking and resolution of customer inquiries and support requests, and the use of AI and machine learning functionalities to assist with, automate and improve customer support operations.– Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021).
– Zendesk,  Inc. is an active participant in the EU-US Data Privacy Framework.
– Storage and processing of all Controller data in data centers in the EU.
– Encryption of all data with industry-standard encryption products: 
Encryption at Rest via AES-256.
Encryption in Transit via TLS 1.2+.
– Zendesk  Inc. is ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 2 Type II, ISO 42001 and CSA STAR Levels 1 & 2 certified.
– More information: 
https://www.zendesk.com/trust-center/
EU
Amplitude Inc. 
201 3rd Street, Suite 200, 
San Francisco, CA
94103
USA
Non-optionalProvision of product analytics services for tracking and analysing user interactions within the SoSafe Platform, enabling measurement of feature adoption, analysis of user journeys, and data-driven product improvements– Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021).
– Amplitude, Inc. is an active participant in the EU-US Data Privacy Framework.
– Storage and processing of all Controller data in data centers located in the EU.
– Encryption of all data with industry-standard encryption products: 
Encryption at Rest via AES 256
Encryption in Transit via TLS 1.2+
– Amplitude, Inc. is ISO 27001, ISO 27017, ISO 27018 and SOC 2 Type II certified.
– More information: https://amplitude.com/security-and-privacy and https://trust.amplitude.com/?tab=overview 
EU
Lingo.dev (Replexica, Inc.)
2261 Market Street STE 46186,
San Francisco, California 94114
USA
OptionalAI-driven localization of product UI strings and content at build time, including processing of translation APIs, glossaries, and brand voice guidelines.
This provider is only required to the extent the Controller enables the usage of AI.
– Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021).
– Storage and processing of all Controller data in data centers located in the EU.
– Encryption of all data with industry-standard encryption products:
Encryption at Rest via AES 256
Encryption in Transit via TLS 1.2+
– Lingo.dev is SOC Type II certified.
– More information: https://trust.delve.co/lingo.dev 
– Transfer Impact Assessment (TIA) conducted by SoSafe’s  external Data Protection Officer.
EU
Vonage B.V.
Radarweg 29A, Office 10.42, 
1043 NX Amsterdam 
The Netherlands
OptionalProvision of mobile services for conducting Smishing Simulations.
This provider is only required to the extent the Controller activated Smishing features.
– Conclusion of a data processing agreement.
– Storage and processing of all Controller data in data centers located in the  EU. 
– Encryption of all data with industry-standard encryption products:
Encryption at Rest via AES-256.
Encryption in Transit via TLS 1.2+ for API, and SRTP for actual voice and video data transmitted during a VoIP call. 
– Vonage B.V. is ISO 27001 and SOC 2 Type II certified.
– More information: https://www.vonage.com/security/. and https://www.vonage.com/legal/technical-organizational-security-practices/ .
EU
Eleven Labs Inc.


169 Madison Ave #2484 
New York, NY 10016
USA
OptionalProvision of AI-powered generative voice technology used to conduct vishing simulations via AI voice agents and to generate cloned voices from audio samples that replicate an individual’s vocal characteristics (subject to the individual’s explicit consent)
This provider is only required to the extent the Controller activated Vishing features.
– Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021).
– Eleven Labs Inc. is an active participant in the EU-US Data Privacy Framework.
–  Storage and processing of all Controller data in data centers located in the EU.
– Encryption of all data with industry-standard encryption products:
Encryption at Rest via AES-256. 
Encryption in Transit viaTLS 1.2+. 
– Eleven Labs Inc. is ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type II and CSA Star Level 1 certified.
– More information: https://compliance.elevenlabs.io/    
EU
Leen, Inc. (dba Leen.dev)
Delaware 52 2nd Street, Floor 3, San Francisco CA 94105
USA
OptionalScalable security tool integrations, enabling the ingestion and processing of third-party security signals.
This provider is only required to the extent the Controller requests security stack  integration.
– Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021).
– Storage and processing of all Controller data in data centers located in the EU.
– Encryption of all data with industry-standard encryption products:
Encryption at Rest via AES-256 and key management is handled via AWS KMS.
Encryption in Transit via TLS 1.2+
– Leen.dev is SOC 2 Type II certified.
– More information : https://www.leen.dev/ 
– Transfer Impact Assessment (TIA) conducted by SoSafe’s  external Data Protection Officer.
EU
Google Cloud EMEA Ltd 
70 Sir John Rogerson’s Quay 
Dublin 2
Ireland
Optional Provision of interactive support, text creation and analysis, and other AI-powered tools. This provider is only required to the extent the Controller enables the usage of AI.– Conclusion of a data processing agreement.
– Storage and processing of all Controller data in data centers located in the EU. 
– Encryption of all data with industry-standard encryption products:
Encryption at Rest via AES-256 
Encryption in Transit via  TLS 1.3
– Google Cloud is ISO 27001, ISO 42001, SOC 2 and SOC 3 certified.
– More information: https://cloud.google.com/compliance?hl=en 
EU
Anthropic Ireland, Ltd
6th Floor South Bank House,
Barrow Street,
Dublin 4, Dublin 
Ireland
OptionalProvision of interactive support, text creation and analysis, and other AI-powered tools. 
This provider is only required to the extent the Controller enables the usage of AI.
– Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021).
– Encryption of all data with industry-standard encryption products :
Encryption at Rest via AES-256 GCM
Encryption in Transit via  TLS 1.2+
– Anthropic Ireland, Ltd  is ISO27001, ISO 42001, SOC 2 Type II and CSA STAR Level 2 certified.
– More information: https://trust.anthropic.com/ 
– Transfer Impact Assessment (TIA) conducted by SoSafe’s  external Data Protection Officer.
US 

Experience our products first-hand

Use our online test environment to see how our platform can help you empower your team to continuously avert cyber threats and keep your organization secure.

SoSafe Security Awareness Training Leader Enterprise 2026 Sosafe Cyber security training platform top 50 award 2026 SoSafe Security Awareness Training Leader 2026 SoSafe Security Awareness Training Momentum Leader 2026 SoSafe Security Awareness Training Leader Mid-Market 2026 SoSafe Security Awareness Training Leader Europe 2026

This page is not available in English yet.

Diese Seite ist noch nicht in Ihrer Sprache verfügbar. Sie können auf Englisch fortfahren oder zur deutschen Startseite zurückkehren.

Cette page n’est pas encore disponible dans votre langue. Vous pouvez continuer en anglais ou revenir à la page d’accueil en français.

Deze pagina is nog niet beschikbaar in uw taal. U kunt doorgaan in het Engels of terugkeren naar de Nederlandse startpagina.

Esta página aún no está disponible en español. Puedes continuar en inglés o volver a la página de inicio en español.

Questa pagina non è ancora disponibile nella tua lingua. Puoi continuare in inglese oppure tornare alla home page in italiano.