S1. About This List
Core service providers process information on CVP's behalf to deliver business and product functions. External assessment data sources receive limited technical queries and return public intelligence used in Lens findings. A provider's legal classification may depend on its terms and the processing context; inclusion here is intended to make the data flow transparent.
S2. Core Service Providers
| Provider | Purpose | Information involved |
|---|---|---|
| Microsoft Azure | Application hosting, PostgreSQL database, queues, backups, and secrets management | Account, Customer, assessment, operational, and security data |
| Cloudflare | DNS, TLS, web delivery, security, form protection, and R2 evidence storage | Web traffic and request metadata; assessment evidence stored in R2 |
| Stripe | Checkout, subscriptions, invoicing, tax, payment processing, and customer billing portal | Billing contacts, subscription and transaction metadata, and payment information; no assessment evidence |
| Microsoft 365 / Graph | Transactional email and support correspondence | Recipient addresses and message content, including invitations and service notices |
| Microsoft Entra | Optional federated sign-in | Identity claims such as name, email, organization identifier, and authentication metadata |
| Google Workspace | Optional federated sign-in | Identity claims such as name, email, hosted-domain identifier, and authentication metadata |
S3. Assessment Data Sources
| Source | Purpose | Query information |
|---|---|---|
| crt.sh and Cert Spotter | Public certificate-transparency and subdomain discovery | Customer domain or hostname and ordinary request metadata |
| Shodan InternetDB | Public IP, port, service, and exposure intelligence | Customer public IP address and ordinary request metadata |
| Have I Been Pwned | Public domain-related breach intelligence | Customer domain and ordinary request metadata |
| MXToolbox | Public email and DNS posture checks | Customer domain and ordinary request metadata |
| NIST National Vulnerability Database | CVE detail and severity enrichment | CVE identifier and ordinary request metadata |
Lens also performs direct DNS lookups and authorized network and web probes against Customer-designated targets and related public-facing assets discovered during an assessment.
S4. Changes
CVP updates this page when a principal provider or assessment source changes. The effective date above shows the latest revision. Any additional notice rights in an Enterprise agreement or data-processing agreement continue to apply.
S5. Contact
Questions about providers, processing locations, or data flows may be sent to [email protected]. Contractual questions may be sent to [email protected].