Providers and reports

The services that may handle data, where they work, and which security proof is available.

01

Which service providers can process data?

We list the main product, support, AI, analytics, and website services used by our current product below.

A provider only receives data needed for its job and the feature in use. Google, Microsoft, and LinkedIn can also be user-chosen data sources, not only providers working for us.

Current service provider list

Provider
Job
Data involved
Usual area
Hetzner API, database, file, and backup hosting Core product and account data Germany and Finland
Vercel Public website and front-end delivery Web requests, device and network data Global network
Auth0 (Okta) Login and identity Identity, email, and sign-in data EU and US services
Google Connected account APIs, Gemini, and website analytics Connected Google data, AI inputs, or web use data Global
Microsoft Connected account APIs and Azure OpenAI Connected Microsoft data or AI inputs Global
LinkedIn Sign-in and connected profile source Profile and account data EU and global
Unipile LinkedIn sync Profiles, connections, searches, and messages France
Apollo Professional data enrichment Work email and profile clues United States
Serper Web search for enrichment Name, company, domain, and search terms Global
Reverse Contact Professional data enrichment Work email France
OpenAI AI search and result checks Prompt and selected product context United States and contracted regions
Sentry Error tracking Diagnostics and limited account context EU and US services
Resend Service email Recipient, subject, and message content United States
PostHog Product analytics Account and product use events EU cloud, Germany
Slack Internal service alerts Alert and error context, which may include an account email United States
iubenda Legal and cookie pages Website request and consent data EU and global
02

Are connected data sources the same as sub-processors?

Not always.

A connected service such as Google or Microsoft gives us data at the user's request. The same company may also provide a cloud or AI service to us. The legal role depends on that job.

Public and paid professional data sources can also supply facts without acting as a host for our product.

03

How can a customer track provider changes?

We keep the public list on this page current. Our DPA sets the notice terms for customer contracts.

The DPA covers new provider notice and the customer's right to raise a reasoned data protection concern.

04

How do you check a service provider before using it?

We review the data involved, access, encryption, location, retention, breach terms, and security proof.

The depth of the review follows the risk. A provider that can handle email, calendar, login, or production data gets a stricter review than a low-risk website service.

We keep the provider list, data flows, and risk notes with our security records.

05

What contract terms apply to service providers?

Our DPA requires each provider to protect customer data under terms that match the work it performs.

The terms cover confidentiality, security, limited use, privacy-law duties, and return or deletion where they apply.

When data moves outside the EEA or UK, we use an approved transfer basis where the law requires one.

06

Is Graph One SOC 2 or ISO 27001 certified?

We are CASA Tier 2 certified. We do not claim SOC 2 or ISO 27001 certification for Graph One.

Some providers have their own certificates. For example, Hetzner states that its data-center information security system has ISO 27001:2022 certification. That provider certificate does not certify us as a company.

07

Has an outside party reviewed Graph One security?

Yes. We hold current CASA Tier 2 certification. TAC Security completed our latest revalidation on February 26, 2026.

Google requires an annual security assessment for apps that use restricted Google user-data scopes. We need this review to keep our Google data access.

The report gives us an ESOF Cyber Score of 9.7 out of 10. Contact us for the current evidence package.

Certification
CASA Tier 2
Latest revalidation
26 February 2026
ESOF Cyber Score
9.7 / 10
08

What does the CASA Tier 2 review cover?

It reviews application security controls against checks based on the OWASP Application Security Verification Standard.

The review covers areas such as access control, secure data handling, input safety, browser and API controls, cryptography, build settings, and production setup.

CASA is not a SOC 2 audit, an ISO 27001 certificate, or a legal opinion on privacy law. We state its scope so customers can judge the proof correctly.

09

Which security evidence can a customer request?

Ask us for the current CASA proof, policy summaries, control answers, or the latest relevant test record.

We match the evidence to the product, data, and control under review. Some reports need an NDA or limited sharing because they contain security details.

We will say when a document shows a planned control rather than proof that the control ran.

10

Can Graph One answer a security or privacy questionnaire?

Yes. Send it to contact@graph.one.

Include the due date, product scope, data types, and any proof you need. We will state when a control belongs to a provider or when a claim is not yet backed by current evidence.