Legal & trust

Data Processing Agreement

Last updated 8 July 2026

Most GRC vendors need a heavyweight DPA because they hold your data. We designed that risk away — so ours is short, and it's available on request.

Available on request

A GDPR Article 28-compliant DPA is available to customers and prospects on request. Ask via the privacy contact and we'll provide the current version for signature.

Why our processing scope is small

The GRC Solo product is federated: it runs as one install per company, on your infrastructure. Your security evidence, secrets, and operational data never enter our systems — so for that data we are not a processor at all. We can't lose, leak, or be compelled to produce data we never receive. Our data-flow makes this the headline exhibit, not a footnote.

What we do process

For this website, the only personal data we process is the email you submit, as described in our Privacy Policy, using the vendors on our subprocessor list. The DPA covers this scope and any additional processing introduced by paid product features.

Subprocessors & changes

Our current subprocessors, with function and region, are published at /subprocessors. The DPA includes a mechanism to notify you of changes and to object.

Data Processing Agreement — GRC Solo