Privacy Policy
We at Rescana Ltd. ("Rescana", "us", "we", or "our") recognize and respect the importance of maintaining the privacy of our customers. This Privacy Notice describes the types of information we collect from you when you use our cyber risk management platform ("Platform"), visit our website ("Site") and/or use the services available thereon ("Services"). This Privacy Notice also explains how we process, transfer, store and disclose the information collected, as well as your ability to control certain uses of the collected information. If not otherwise defined herein, capitalized terms have the meaning given to them in the Terms of Service, available at https://rescana.com/terms ("Terms"). "You" means an individual using the Services.
If you are an individual located in the European Union ("EU Individual"), the United Kingdom, or Switzerland, some additional terms and rights may apply to you, as detailed herein. Rescana Ltd. is the data controller in respect of the processing activities outlined in this Privacy Notice. Our address is 45 Rothschild Blvd., Tel Aviv 6578403, Israel and our registration number is 515442077.
"Personal Data" means any information that refers, is related to, or is associated with an identified or identifiable individual or as otherwise may be defined by applicable law. This Privacy Notice details which Personal Data is collected by us in connection with provision of the Services.
1. Personal Data We Collect, Uses and Legal Basis
Depending on your usage, we collect different types of data and we and any of our third-party sub-contractors and service providers use the data we collect for different purposes, as specified below. It is your voluntary decision whether to provide us with certain Personal Data, but if you refuse to provide such Personal Data, we may not be able to register you to the Platform and/or provide you with the Services or part thereof.
1.1. Registration Data – In order to use our Platform and/or receive related Services, you will be required to register and provide us with your email address. You may also choose to provide additional information, such as your full name. If you use the Services by logging in through a third-party login/account registration service we also may receive Personal Data about you as provided by such third-party service such as your username, email address, a token, and a timestamp.
How we use this data: (1) to provide you with the Platform and/or Services, to respond to your inquiries and requests, and to contact and communicate with you; and (2) to prevent fraud, protect the security of and address any problems with the Platform.
Legal Basis: (1) We process this Personal Data for the purpose of providing the Services to you or the Company with which you are affiliated, which is considered performance of a contract with you or the Company, including responding to your inquiries and requests and providing customer support. (2) When we process your Personal Data for the purposes of preventing fraud, protecting the security of and/or addressing problems with the Site and Services, such processing is based on our legitimate interests.
1.2. Contact Information – When you request information from us, or contact us for any other reason, we will collect any data you provide, such as your name, email address, phone number and the content of your inquiry.
How we use this data: To respond to your request or inquiry.
Legal Basis: We process this Personal Data based on performance of a contract when we respond to your inquiry.
1.3. Automatically Collected Data – When you visit the Site or use the Platform, we automatically collect information about your computer, including non-Personal Data such as your operating system, and Personal Data such as IP address, device ID, and subject to your consent as may be required under applicable law, (geo) location.
How we use this data: (1) to provide you with the Services; (2) to review usage and operations, including in an aggregated non-specific analytical manner, develop new products or services and improve current content, products, and Services; and (3) to prevent fraud, protect the security of our Platform, Site, and Services, and address any problems with the Platform, Site, and/or Services.
Legal Basis: We process this Personal Data for the purpose of providing the Services to you or the Company with which you are affiliated, which is considered performance of a contract with you or the Company. We also process this Personal Data for our legitimate interests to develop and improve our products and Services, review usage, perform analytics, prevent fraud, for our recordkeeping and protection of our legal rights.
1.4. Data Scanning – As part of our Services, we automatically scan the internet and public databases to see whether details such as your name, email address, or Company have become publicly accessible. As described in Section 4, the content we collect through scanning may be analyzed using large language models operated by the AI sub-processors listed in the Annex to this Privacy Notice.
How we use this data: To provide you or the Company with the Services.
Legal Basis: We process this Personal Data for the purpose of performance of a contract with you or the Company, as applicable.
1.5. Materials You Upload – Any materials including documents, photos, and presentations you may upload to the Platform will be collected by us. As described in Section 4, the content of these materials may be processed using large language models operated by the AI sub-processors listed in the Annex to this Privacy Notice in order to generate the assessments, summaries and findings that form part of the Services.
How we use this data: To provide you or the Company with the Services.
Legal Basis: We process this Personal Data for the purpose of performance of a contract with you or the Company, as applicable.
2. Additional Uses
2.1. Statistical Information and Analytics. We and/or our service providers use analytics and marketing-automation tools to collect and analyze information about the use of the Site and/or Services, such as how often users visit the Site, which pages they visit when they do so, and how they arrived at the Site. The tools we currently use across the Site are:
2.1.1. HubSpot – website analytics and marketing automation. HubSpot sets cookies that allow us to recognize a returning visitor across sessions and to link Site activity to an existing contact record where one exists. See https://legal.hubspot.com/privacy-policy.
2.1.2. Analytics and marketing cookies are set in accordance with your cookie choices, as described in Section 9. Strictly necessary cookies are set without consent because the Site cannot function without them.
2.1.3. By analyzing the information we receive, we may compile statistical information across a variety of platforms and users, which helps us improve our Site and Services, understand trends and customer needs, consider new products and services, and tailor existing products and services to customer desires. Some of this information, such as an IP address or a cookie identifier, is Personal Data as described in Section 1.3, and we treat it as such. Where we compile statistics that are aggregated so that they no longer identify any individual, we may share those aggregated statistics with our partners on commercial terms that we determine.
Legal Basis: We process this Personal Data on the basis of your consent where consent is required for the relevant cookie or similar technology, and otherwise for our legitimate interests in understanding and improving the use of our Site and Services.
3. Sharing the Personal Data We Collect
We share your information, including Personal Data, as follows:
3.1. Service Providers, and Subcontractors. We disclose information, including Personal Data we collect from and/or about you, to our trusted service providers and subcontractors, who have agreed to confidentiality restrictions and who use such information solely on our behalf in order to: (1) help us provide you with the Site, Platform and/or Services; and (2) aid in their understanding of how users are using our Site, Platform and/or Services. Such service providers and subcontractors provide us with IT and system administration services, cloud hosting, data backup, security, and storage services, data analysis, natural language processing and other AI model inference, threat and breach intelligence, customer relationship management, and email delivery. The sub-processors we engage when acting as a processor on behalf of our customers are listed in the Annex to this Privacy Notice.
3.2. Business Transfers. Your Personal Data may be disclosed as part of, or during negotiations of, any merger, sale of company assets or acquisition (including in cases of liquidation) in such case, your Personal Data shall continue being subject to the provisions of this Privacy Notice.
3.3. Law Enforcement Related Disclosure. We may share your Personal Data with third parties: (i) if we believe in good faith that disclosure is appropriate to protect our or a third party's rights, property or safety (including the enforcement of the Terms and this Privacy Notice); (ii) when required by law, regulation subpoena, court order or other law enforcement related issues, agencies and/or authorities; or (iii) as is necessary to comply with any legal and/or regulatory obligation.
3.4. Legal Uses. We may use your Personal Data as required or permitted by any applicable law, for example, to comply with audit and other legal requirements.
3.5. No Sale of Personal Data. We do not sell Personal Data, and we do not share Personal Data for cross-context behavioral advertising or targeted advertising, as those terms are defined under applicable United States state privacy laws.
4. AI and Agent Processing
Rescana runs AI agents on your behalf as part of the Services. This section explains how Personal Data is handled in that context.
4.1. Where We Provide the Model. By default, the Services use large language models operated by the AI providers identified in the Annex to this Privacy Notice, together with the location in which they process data. To generate assessments, summaries, classifications and findings we send content processed by the Services – which may include Registration Data, materials you upload under Section 1.5, and data gathered by scanning under Section 1.4 – to those providers.
4.2. Where You Provide the Model. The Company may instead configure the Services to use a model endpoint that it designates, including a model hosted in the Company's own cloud tenancy or operated under the Company's own agreement with a model provider. Where the Company does so: (i) we send that content to the designated endpoint and not to the providers listed in the Annex; (ii) that provider is not our sub-processor in respect of that content; and (iii) the processing, retention and training terms applicable to that content are those of the Company's agreement with that provider, and not ours.
4.3. No Training on Your Data. We do not use customer data to train models. Where we provide the model, our agreements with the providers identified in the Annex prohibit the use of your content to train their foundation models. Where the Company designates its own model endpoint, training is governed by the Company's agreement with that provider.
4.4. Retention of Prompts and Outputs. Prompts and outputs are processed in order to deliver the Services and are not retained by us beyond what that requires. Any retention by a model provider is governed by our agreement with that provider where we provide the model, and by the Company's agreement with its provider where the Company designates its own model endpoint.
4.5. Bounded Autonomy. Our agents operate within defined guardrails and scopes, and sensitive or high-impact actions are designed to keep a human in the loop.
4.6. Acceptable Use. Your use of our AI features is additionally governed by our AI Terms, available at https://rescana.com/ai-terms-1.
4.7. Transfers. Where an AI provider processes data outside your jurisdiction, the transfer safeguards described in Section 5 apply. Where the Company designates its own model endpoint, the Company determines the location in which that processing takes place.
5. International Transfer
5.1. We use subcontractors and service providers who are located in countries other than your own, and send them information we receive (including Personal Data). We conduct such international transfers for the purposes described above. We will ensure that these third parties will be subject to written agreements ensuring the same level of privacy and data protection as set forth in this Privacy Notice, including appropriate remedies in the event of the violation of your data protection rights in such third country.
5.2. Whenever we transfer your Personal Data to third parties based outside of the European Economic Area ("EEA"), we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
5.2.1. Adequacy. We transfer Personal Data to countries, territories or sectors that the European Commission has decided provide an adequate level of protection for Personal Data. This includes transfers to recipients in the United States that are certified under the EU-US Data Privacy Framework, which the European Commission recognized as adequate in its decision of 10 July 2023.
5.2.2. Standard Contractual Clauses. Where we use service providers that are not covered by an adequacy decision, we enter into the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, which give Personal Data protection equivalent to that which it has in the EEA. Where required, we supplement those clauses with a transfer impact assessment and additional technical and organizational measures.
5.2.3. Derogations. In limited cases we may rely on a derogation permitted under Article 49 of the GDPR, for example where the transfer is necessary for the performance of a contract with you.
5.3. For transfers of Personal Data out of the United Kingdom we rely on UK adequacy regulations or on the International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner. For transfers out of Switzerland we rely on Swiss adequacy decisions or on the Standard Contractual Clauses as recognized by the Swiss Federal Data Protection and Information Commissioner, including the Swiss-US Data Privacy Framework where applicable.
5.4. Please contact us at legal@rescana.com if you would like further information on the specific mechanism used by us when transferring your Personal Data out of the EEA, the United Kingdom or Switzerland, or if you would like a copy of the safeguards we have put in place.
6. Security
We have implemented and maintain appropriate technical and organization security measures, policies and procedures designed to reduce the risk of accidental destruction or loss, or the unauthorized disclosure or access to Personal Data appropriate to the nature of such data. The measures we take include:
6.1. Safeguards – The physical, electronic, and procedural safeguards we employ to protect your Personal Data include secure servers, firewalls, antivirus, network segmentation, and encryption of data.
6.2. Access Control – We dedicate efforts for a proper management of system entries and limit access only to authorized personnel on a need to know basis of least privilege rules, review permissions quarterly, and revoke access immediately after employee termination.
6.3. Internal Policies – We maintain and regularly review and update our privacy related and information security policies.
6.4. Personnel – We require new employees to sign non-disclosure agreements according to applicable law and industry customary practice.
6.5. Encryption – We encrypt data in transit using TLS, and data at rest using AES-256.
6.6. Tenant Isolation – We maintain logical isolation between customer tenants.
6.7. Standards and Certifications – We have completed a SOC 2 Type II audit of our security, availability and confidentiality controls, and we are certified as compliant with ISO 27001 (Information Security Management) and ISO 27018 (Cloud Privacy). Our SOC 2 Type II report and ISO certificates are available to customers and prospects under NDA on request, together with our Data Processing Agreement. Further detail on our security posture is available in our Trust Center at https://rescana.com/trust.
6.8. Database Backup – Our databases are backed up on a periodic basis for certain data. Backups are encrypted, tested regularly through restore tests to ensure availability and integrity, and accessible only by authorized personnel.
6.9. Monitoring and Incident Response – We monitor and alert on our production environment and maintain a documented incident response process. Where a personal data breach occurs, we will notify the relevant supervisory authority and affected individuals or customers to the extent and within the timeframes required by applicable law, and we will notify our customers without undue delay where we process Personal Data on their behalf.
6.10. However, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
6.11. As the security of information depends in part on the security of the computer you use to communicate with us and the security you use to protect user IDs and passwords, please take appropriate measures to protect this information.
7. Your Rights – How to Access and Limit Our Use of Certain Personal Data
Subject to applicable law and certain exemptions, and in some cases dependent upon the processing activity we are undertaking, you have certain rights in relation to the Personal Data that we hold about you, as detailed below. We will investigate and attempt to resolve complaints and disputes and make every reasonable effort to honour your wish to exercise your rights as quickly as possible and, in any event, within the timescales provided by applicable data protection laws. We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information and/or comply with any of your requests, as detailed below. You will not be discriminated against for exercising any of these rights:
7.1. Right of Access. You have a right to know what Personal Data we collect about you and, in some cases, to have such Personal Data communicated to you. Subject to applicable law, we may charge you with a fee. Please note that we may not be able to provide you with all the information you request, and, in such case, we will endeavor to explain to you why.
7.2. Right to Data Portability. If the processing is based on your consent or performance of a contract with you and processing is being carried out by automated means, you may be entitled to (request that we) provide you or another party with a copy of the Personal Data you provided to us in a structured, commonly-used, and machine-readable format.
7.3. Right to Correct Personal Data. Subject to the limitations in applicable law, you may request that we update, complete, correct or delete inaccurate, incomplete, or outdated Personal Data.
7.4. Deletion of Personal Data ("Right to Be Forgotten"). If you are an EU Individual, you have a right to request that we delete your Personal Data if either: (i) it is no longer needed for the purpose for which it was collected, (ii) our processing was based on your consent and you have withdrawn your consent, (iii) you have successfully exercised your Right to Object (see below), (iv) processing was unlawful, or (v) we are required to erase it for compliance with a legal obligation. We cannot restore information once it has been deleted. Please note that to ensure that we do not collect any further Personal Data, you should terminate your account with us, and clear our cookies from any device where you have visited our Site or Platform. We may retain certain Personal Data (including following your request to delete) for audit and record-keeping purposes, or as otherwise permitted and/or required under applicable law.
7.5. Right to Restrict Processing. If you are an EU Individual, you can ask us to limit the processing of your Personal Data if either: (i) you have contested its accuracy and wish us to limit processing until this is verified; (ii) the processing is unlawful, but you do not wish us to erase the Personal Data; (iii) it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise, or defend of a legal claim; (iv) you have exercised your Right to Object (below) and we are in the process of verifying our legitimate grounds for processing. We may continue to use your Personal Data after a restriction request under certain circumstances.
7.6. Right to Object. If you are an EU Individual, you can object to any processing of your Personal Data which has our legitimate interests as its legal basis, if you believe your fundamental rights and freedoms outweigh our legitimate interests. If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.
7.7. Withdrawal of Consent. You may withdraw your consent in connection with any processing of your Personal Data based on a previously granted consent. This will not affect the lawfulness of any processing prior to such withdrawal.
7.8. Right to Lodge a Complaint with Your Local Supervisory Authority. If you are an EU Individual, you may have the right to submit a complaint to the relevant supervisory data protection authority if you have any concerns about how we are processing your Personal Data, though we ask that as a courtesy you please attempt to resolve any issues with us first.
7.9. How to Exercise Your Rights. To exercise any of the rights above, contact us at legal@rescana.com. Where we process Personal Data as a processor on behalf of one of our customers, we will refer your request to that customer, who is the controller of that data, and will assist them in responding to it.
8. Data Retention
8.1. Subject to applicable law, we retain Personal Data as necessary for the purposes set forth above, in accordance with our internal data retention and deletion policy. We may delete information from our systems without notice to you once we deem it is no longer necessary for these purposes. Retention by any of our processors may vary in accordance with the processor's retention policy.
8.2. We set retention periods for each category of Personal Data in an internal retention schedule, which we review periodically. Where more than one retention ground applies to the same data, the longest applicable period governs. The criteria we apply are:
8.2.1. Registration Data and materials you upload – retained while the account is active, then for the period agreed with the Company with which you are affiliated, and thereafter until the data ages out of our then-current backup cycle.
8.2.2. Contact Information – retained until your inquiry is closed and for a further period during which we may reasonably expect follow-up correspondence, after which it is deleted or archived in minimal form.
8.2.3. Data collected by scanning – retained for as long as it remains relevant to the current risk assessment we provide to the Company, plus a limited history so that changes over time can be shown.
8.2.4. Automatically collected data and logs – retained for the period necessary to operate, secure and troubleshoot the Services, with security-relevant logs kept longer than operational logs where required by applicable law.
8.2.5. Marketing data – retained until you opt out or your engagement with us lapses. We keep a minimal suppression record indefinitely, because we need it in order to continue honouring your opt-out.
8.2.6. Records we are required to keep – accounting, tax and audit records are retained for the seven-year period required under Israeli law, and records relevant to a potential or actual legal claim are retained until the applicable limitation period expires.
8.2.7. Prompts and outputs sent to AI models – retained as described in Section 4.4.
8.3. In some circumstances, we may store your Personal Data for longer periods of time, for instance where we are required to do so in accordance with legal, regulatory, tax, audit, accounting requirements and so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your Personal Data or dealings. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data, and whether those purposes can be achieved through other means, as well as applicable legal requirements.
8.4. Please contact us at legal@rescana.com if you would like details regarding the retention periods for different types of your Personal Data.
9. Cookies and Similar Technologies
We use cookies and similar technologies for a number of reasons, including to help personalize your experience. Third parties through which we provide the Services and/or our business partners may be placing and reading cookies on your browser.
9.1. What are Cookies? A cookie is a small piece of text that is sent to a user's browser or device. The browser provides this piece of text to the device of the originating user when this user returns.
9.1.1. A "session cookie" is temporary and will remain on your device until you leave the Site.
9.1.2. A "persistent" cookie may be used to help save your settings and customizations across visits. It will remain on your device until you delete it.
9.1.3. First-party cookies are placed by us, while third-party cookies may be placed by a third party. We use both first- and third-party cookies.
9.1.4. We may use the terms "cookies" to refer to all technologies that we may use to store data in your browser or device or that collect information or help us identify you in the manner described above, such as web beacons or "pixel tags".
9.2. How We Use Cookies. We use cookies and similar technologies in the following categories:
9.2.1. Strictly necessary – required to operate the Site and Platform, to authenticate you, to maintain your session, to remember your cookie preferences, and to keep the Site secure. These are set without your consent because the Site cannot function without them.
9.2.2. Analytics and performance – used to understand how visitors use the Site so that we can measure and improve it, including the tools described in Section 2.1.
9.2.3. Functionality – used to remember choices you make and to personalize your experience of the Site.
9.2.4. Marketing – used to understand which of our campaigns and content bring visitors to the Site, and to associate Site activity with a contact record in our customer relationship management system.
9.3. Your Cookie Choices. Where required by the law applicable in your location, we present a cookie consent banner on your first visit to the Site, which allows you to accept or decline the categories of cookies that are not strictly necessary. Where the banner is presented to you, we do not set analytics, functionality or marketing cookies before you have consented to the relevant category, and you can change or withdraw your choice at any time by reopening the cookie preferences from the banner. Your choice is remembered for future visits. Where the banner is not presented to you, you can control cookies using the browser settings described in Section 9.4, and you may contact us at legal@rescana.com to ask us to stop setting non-essential cookies for you.
9.4. Browser Controls. Independently of the banner, most Web browsers are initially configured to accept cookies, but you can change this setting so your browser either refuses all cookies or informs you when a cookie is being sent. In addition, you are free to delete any existing cookies at any time. Please note that some features of the Services may not function properly when cookies are disabled or removed. For example, if you delete cookies that store your account information or preferences, you will be required to input these each time you visit.
10. Additional Rights in Specific Jurisdictions
10.1. United Kingdom. If you are located in the United Kingdom, the rights described in Section 7 apply to you under the UK GDPR and the Data Protection Act 2018 on the same terms as they apply to EU Individuals, and references to a supervisory authority include the UK Information Commissioner's Office.
10.2. Switzerland. If you are located in Switzerland, the rights described in Section 7 apply to you under the Swiss Federal Act on Data Protection, and references to a supervisory authority include the Swiss Federal Data Protection and Information Commissioner.
10.3. California and other United States states. If you are a resident of California or of another United States state with a comprehensive privacy law, you may have the right to know the categories of personal information we have collected about you, the categories of sources, the purposes for collecting it, and the categories of third parties to whom we disclose it – all of which are described in Sections 1, 2 and 3 – as well as the right to request access to, correction of, and deletion of your personal information, and the right not to be discriminated against for exercising these rights. As stated in Section 3.5, we do not sell personal information and we do not share it for cross-context behavioral advertising, and we do not process personal information for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects. You may exercise these rights, or submit a request through an authorized agent, by contacting us at legal@rescana.com.
10.4. Israel. Rescana Ltd. is an Israeli company and our processing is subject to the Israeli Privacy Protection Law, 5741-1981 and the regulations enacted under it. If you are located in Israel, you have the right to inspect the Personal Data we hold about you and to request that it be corrected or deleted, and you may contact us at legal@rescana.com to do so.
11. Third-Party Applications and Services
All use of third-party applications or services is at your own risk and subject to such third party's terms and privacy policies.
12. Communications
12.1. We reserve the right to send you service-related communications, including service announcements and administrative messages, without offering you the opportunity to opt out of receiving them. Should you not wish to receive such communications, you may cancel your account.
12.2. Where we send you marketing communications, we do so in accordance with applicable law, including on the basis of your consent where consent is required. You may opt out of marketing communications at any time by using the unsubscribe link included in every marketing email we send, or by contacting us at legal@rescana.com. Opting out of marketing communications will not stop the service-related communications described in Section 12.1.
13. Children
We do not knowingly collect Personal Data from children under the age of sixteen (16). In the event that you become aware that an individual under the age of sixteen (16) has registered without parental permission, please advise us immediately.
14. Changes to the Privacy Notice
14.1. We may update this Privacy Notice from time to time to keep it up to date with legal requirements and the way we operate our business, and we will place any updates on this webpage together with a revised "Last updated" date. Please come back to this page every now and then to make sure you are familiar with the latest version. If we make material changes to this Privacy Notice, we will seek to inform you by notice on our Site or per email.
14.2. We may also add, replace or remove sub-processors listed in the Annex. Where we act as a processor on behalf of a customer, we will give that customer notice of intended changes to our sub-processors in accordance with the Data Processing Agreement between us, so that they have an opportunity to object. Customers and prospects can subscribe to sub-processor change notifications by contacting legal@rescana.com.
15. Comments and Questions
If you have any comments or questions about this Privacy Notice or if you wish to exercise any of your legal rights as set out herein, please contact us at legal@rescana.com.
Annex – List of Rescana's Sub-Processors
When acting as a data processor on behalf of our customers, Rescana engages sub-processors who may process Customer Personal Data submitted to Rescana's services. These sub-processors are listed below, with a description of the types of processing they perform and the location in which they perform it. This list may be updated by Rescana from time to time in accordance with Section 14.2. The same list is published in our Trust Center at https://rescana.com/trust#subprocessors.
The AI providers listed below apply where Rescana provides the model. Where a customer designates its own model endpoint under Section 4.2, that provider is not a Rescana sub-processor in respect of the content sent to it.
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenAI | Natural language processing | USA |
| AWS | Cloud computing and storage | USA / Global |
| Mixpanel | Product analytics | USA |
| Segment | Customer data infrastructure | USA |
| HubSpot | CRM | USA |
| SendGrid | Email delivery | USA |
| Slack | Secure messaging | USA |
| Have I Been Pwned | Data breach intelligence | Australia |