New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

Subprocessors

The following is a list of subprocessors used by Socket to provide our services, last updated on 25 March 2026.

ActiveCampaign, LLC (Postmark)ProductEmails, login magic linksYes

USA

Sending emails like password reset or login links
Amazon BedrockAI VendorOpen Source Package source code; customer dashboard and/or artifacts (with customer approval)With customer approval

USA

AI inference with other commercial models
Amazon S3ProductOpen Source Package tarballsNo

USA

storage of open source package data
AnthropicAI VendorOpen Source Package source code; customer dashboard and/or artifacts (with customer approval)With customer approval

USA

AI models and inference
BackblazeProductOpen Source Package tarballsNo

USA

storage of open source package data
ClickHouse, IncProductCustomer alert metadataYes

USA

organization alerts and analytics
Functional Software, Inc (dba Sentry)ProductErrors (Product stack traces, customer entity Identifiers)Yes, only exceptions

USA

EU

We use this for tracing and error logging
GCPProductCustomer manifest files, SBOMs, generated alertsYes

USA

service infrastructure
HubSpot, Inc.SalesCustomer conversations, sales, contact infoYes

USA

organizing customer information and sales communications
Linear Orbit, Inc. (Linear)ProductTarballs of manifestsYes

USA

EEA

keeping track of customer issues and maintaining context while providing customer support
MixpanelProductAnalyticsNo

USA

EU

based on Customer’s selection and configuration of the Application Services

for measuring analytics on socket's public websites
n8n GmbH (DBA n8n)ProductAnalytics, Customer conversations, sales, contact infoYes

USA

EU

Automation platform
OpenAIAI VendorOpen Source Packages source code; customer dashboard and/or artifacts (with customer approval)With customer approval

USA

AI models and inference
PlausibleProductAnalyticsNo

EU

measuring traffic on Socket's public package pages
READMEProductDocumentation for socketNo

Documentation knowledge base
SanityProductBlog posts, public content, announcementsNo

USA

Used as a CMS
Slack Technologies, LLCProductLinks to customer data, snippets, customer provided logs, zips, etc..; Scan alerts and notificationsYes

USA

Communication around customer support issues; We have a feature to send notifications to users via slack as an opt-in method
Stripe, LLC.ProductPayment methods, invoices, etc.Yes

Customer-dependent

Depends on user/customer location; see Stripe's terms and conditions

payment processing
TwitterProductMalware announcements and autogenerated news storiesNo

posts social media messages about malware findings
VantaProductScan alerts and notificationsYes (opt-in)

Customer-dependent

Determined by Customer Vanta Account

Enabling customers to save alerts
WorkOSProductSSO settings, user ids, user emails, user namesYes (SSO only)

USA

to support SSO as a login method for socket.dev
ZendutyProductPages and support escalationNo

paging support for incident response