Legal

Sub-processors

Last updated 1 June 2026

VigilPath engages the following sub-processors to deliver the platform. Customers are notified at least 30 days before a new sub-processor is added or a material change is made. Object to a change by writing to dpo@vigilpath.co.uk.

Infrastructure & data

ProviderPurposeLocationTransfer mechanism
Managed PostgreSQL (hyperscaler)Primary application databaseLondon, UKUK domestic
Object storageEncrypted evidence filesLondon, UKUK domestic
CDN / edge computeStatic assets, WAFUK / EU edgeUK adequacy
Email deliveryTransactional and authentication emailsEUUK adequacy
Error monitoringApplication error telemetry (no payload PII)EUUK adequacy

AI / model providers

Agent inference is run against models hosted in UK or EU regions. Customer case material is sent under zero-retention terms; providers do not train on customer data.

How we vet sub-processors

  • Documented security review and data protection assessment.
  • Article 28-compliant data processing terms signed before go-live.
  • Annual review of certifications (ISO 27001, SOC 2) where available.