Coalfire Systems SUB-PROCESSOR LIST
Last updated: October 1st 2025
Coalfire may engage trusted third-party sub-processors to assist in delivering our professional services. When we do so, we maintain full responsibility for service delivery and ensure that:
- All sub-processors are contractually bound to the same confidentiality, security, and data protection standards that apply to Coalfire
- Sub-processors meet our rigorous standards for professional qualifications, security practices, and regulatory compliance
- Client data is protected through appropriate contractual safeguards and technical measures
- We provide transparency by maintaining this current list of authorized sub-processors
Coalfire carefully vets all sub-processors and requires them to comply with applicable laws, industry standards, and our internal policies. We regularly monitor sub-processor performance to ensure continued compliance with our quality and security requirements.
For additional legal terms and procedures governing sub-processor engagement, see our Data Processing Agreement at Coalfire.com/dpa.
Business Operations and Platform Sub-processors
To deliver our professional services and operate our business effectively, Coalfire works with the following authorized sub-processors who provide technical, administrative, marketing, legal, and operational support functions.
Processor | Purpose | Location | Types of data |
|---|---|---|---|
Amazon Web Services | Data storage and collaboration | United States | Client Business Contact Information, Client Data |
Atlassian JIRA | CF1 User Support Platform | United States | Client Business Contact Information |
Avalara | Sales tax software | United States | Client Data |
Bizable/Adobe | Marketing | United States | Client Business Contact Information |
Box.Com | Data storage and collaboration | United States | Client Business Contact Information, Client Data |
Crossbeam | Customer Relationship Management | United States | Client Business Contact Information |
Cvent, Inc. | Marketing | United States | Client Business Contact Information |
Cyera | Security monitoring | United States | Client Business Contact Information, Client Data |
Delighted | Customer Satisfaction | United States | Client Business Contact Information, Client Data |
DemandBase | Marketing | United States | Client Business Contact Information |
Everlaw | E-discovery / litigation support | United States | Client Business Contact Information, Client Data |
Ironclad | Contract Management | United States | Client Business Contact Information |
Microsoft Azure | Data storage and collaboration | United States | Client Business Contact Information, Client Data |
Microsoft Office 365 | Communication | United States | Client Business Contact Information, Client Data |
NewRelic | User Platform Support | United States | Client Business Contact Information |
Outreach | Customer Relationship Management | United States | Client Business Contact Information |
Paramify | Compliance automation | United States | Client Business Contact Information, Client Data |
Pardot | Marketing | United States | Client Business Contact Information |
Proofpoint | Email Security Gateway | United States | Client Business Contact Information, Client Data |
Salesforce | CRM | United States | Client Business Contact Information, Client Data |
Splunk | Security monitoring /SIEM | United States | Client Business Contact Information, Client Data |
Zoom Info | Communication | United States | Client Business Contact Information |
Client Services Sub-processors
These sub-processors are engaged selectively based on specific client requirements and service types. Not all sub-processors are engaged for every client engagement, and typically only one or a subset will be utilized depending on the scope and nature of services being delivered.
Processor | Purpose | Location | Types of data |
|---|---|---|---|
Checkmarx | Services Support | United States | Client Business Contact Information, Client Data |
Cyberhelm Technologies, LLC | Services Support | United States | Client Business Contact Information, Client Data |
First Information Technology Services | Services Support | United States | Client Business Contact Information, Client Data |
GlobalLogic Inc. | Services Support | United States, Argentina | Client Business Contact Information, Client Data |
Growth [period] | Services Support | United States | Client Business Contact Information, Client Data |
Infogain Corporation | Services Support | United States, India | Client Business Contact Information, Client Data |
IRM Authority Inc. | Services Support | United States | Client Business Contact Information, Client Data |
LEET Security SLU | Services Support | Spain | Client Business Contact Information, Client Data |
Meta Defence Labs Ltd | Services Support | United Kingdom | Client Business Contact Information, Client Data |
Rarefield Inc. | Services Support | United States | Client Business Contact Information, Client Data |
Sekuro Operations Pty Ltd (fka Privasec Pte Ltd) | QSA Services | Australia | Client Business Contact Information, Client Data |
SGS North America Inc. | Services Support | Switzerland | Client Business Contact Information, Client Data |
Shared Assessments | Services Support | United States | Client Business Contact Information, Client Data |
For questions about our sub-processors or to exercise data subject rights, contact privacy@coalfire.com.