Sub-Processor Register

  • Organisation: Noviqent Ltd
  • Company number: 17232197, registered in England & Wales
  • ICO registration: ZC225920
  • Publication status: Public, customer-accessible
  • Last updated: 21 August 2026

Current hosting architecture

Which of the platform's three connection tiers your organisation uses determines what, if anything, reaches Noviqent's own servers — this isn't the same for every customer, so read the tier that applies to you.

  • Direct connection (Tier 1). Application, database, and worker infrastructure are operated by Noviqent directly — not outsourced to a third-party cloud platform, so this is disclosed here as infrastructure, not as a sub-processor. Scanning runs on this infrastructure using a narrowly-scoped, read-only role into your cloud account, and the full raw configuration of every scanned resource is stored in Noviqent's database, alongside the cost data, findings, and recommendations computed from it. This is the tier most customers start on.
  • In-account collector (Tier 2). Scanning runs inside your own account or cluster, on your schedule. By default the collector sends only findings and recommendations to Noviqent's infrastructure — raw resource configuration is withheld unless your organisation explicitly opts the collector into including it (INCLUDE_RAW_CONFIG), which trades a smaller data-residency footprint for richer asset drill-down in the dashboard.
  • Fully self-hosted (Tier 3). The entire platform, including the database, runs on your own infrastructure. Nothing reaches Noviqent's servers at all.

Current sub-processors

  • Google Identity Services — used only if you choose "Sign in with Google". Receives your email address, name, and Google account identifier to authenticate you. Never receives cloud resource data, regardless of connection tier.
  • Google reCAPTCHA — used on registration to prevent automated abuse. Receives browser and usage signals. Never receives cloud resource data.

Not currently in use

No third-party email delivery, monitoring, logging, error-tracking, or AI/ML service is currently used to process your account or cloud resource data.

Notice of changes

Noviqent will update this register before enabling a new production sub-processor, and will follow the customer authorisation/notification mechanism set out in your organisation's Data Processing Agreement before adding a material new one. If your organisation needs a signed Data Processing Agreement in place and doesn't already have one — for example, before connecting a production environment on Tier 1 — contact compliance@noviqent.co.uk. See the Privacy Notice for how the three connection tiers affect what personal data is processed and where.