Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Should Subprocessor Lists Be Public? (simpletrustportal.com)
4 points by cadence- 20 days ago | hide | past | favorite | 1 comment


I’ve gotten pushback from customers on this point a few times, so I wrote up my reasoning and wanted to see how others think about it.

My argument is that giving this information to customers who need it is different from publishing it openly to the whole internet. I think many companies treat public subprocessor lists as a default best practice without thinking enough about the security tradeoff.

Would be useful to hear from people who have handled enterprise security reviews, privacy reviews, or trust-center decisions.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: