The following is a list of subprocessors used by Socket to provide our services, last updated on 25 March 2026.
| ActiveCampaign, LLC (Postmark) | Product | Emails, login magic links | Yes | USA | Sending emails like password reset or login links |
| Amazon Bedrock | AI Vendor | Open Source Package source code; customer dashboard and/or artifacts (with customer approval) | With customer approval | USA | AI inference with other commercial models |
| Amazon S3 | Product | Open Source Package tarballs | No | USA | storage of open source package data |
| Anthropic | AI Vendor | Open Source Package source code; customer dashboard and/or artifacts (with customer approval) | With customer approval | USA | AI models and inference |
| Backblaze | Product | Open Source Package tarballs | No | USA | storage of open source package data |
| ClickHouse, Inc | Product | Customer alert metadata | Yes | USA | organization alerts and analytics |
| Functional Software, Inc (dba Sentry) | Product | Errors (Product stack traces, customer entity Identifiers) | Yes, only exceptions | USA EU | We use this for tracing and error logging |
| GCP | Product | Customer manifest files, SBOMs, generated alerts | Yes | USA | service infrastructure |
| HubSpot, Inc. | Sales | Customer conversations, sales, contact info | Yes | USA | organizing customer information and sales communications |
| Linear Orbit, Inc. (Linear) | Product | Tarballs of manifests | Yes | USA EEA | keeping track of customer issues and maintaining context while providing customer support |
| Mixpanel | Product | Analytics | No | USA EU based on Customer’s selection and configuration of the Application Services | for measuring analytics on socket's public websites |
| n8n GmbH (DBA n8n) | Product | Analytics, Customer conversations, sales, contact info | Yes | USA EU | Automation platform |
| OpenAI | AI Vendor | Open Source Packages source code; customer dashboard and/or artifacts (with customer approval) | With customer approval | USA | AI models and inference |
| Plausible | Product | Analytics | No | EU | measuring traffic on Socket's public package pages |
| README | Product | Documentation for socket | No | — | Documentation knowledge base |
| Sanity | Product | Blog posts, public content, announcements | No | USA | Used as a CMS |
| Slack Technologies, LLC | Product | Links to customer data, snippets, customer provided logs, zips, etc..; Scan alerts and notifications | Yes | USA | Communication around customer support issues; We have a feature to send notifications to users via slack as an opt-in method |
| Stripe, LLC. | Product | Payment methods, invoices, etc. | Yes | Customer-dependent Depends on user/customer location; see Stripe's terms and conditions | payment processing |
| Product | Malware announcements and autogenerated news stories | No | — | posts social media messages about malware findings | |
| Vanta | Product | Scan alerts and notifications | Yes (opt-in) | Customer-dependent Determined by Customer Vanta Account | Enabling customers to save alerts |
| WorkOS | Product | SSO settings, user ids, user emails, user names | Yes (SSO only) | USA | to support SSO as a login method for socket.dev |
| Zenduty | Product | Pages and support escalation | No | — | paging support for incident response |