Skip to main content

Supplier Security Policy

This policy describes how Bunker governs the security of its supplier and subprocessor relationships. On that dimension, it implements the principles of our information security policy and covers controls A.5.19 to A.5.23 of the Statement of Applicability.

Status regarding the ISO/IEC 27001 standard

Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment.

Purpose and scope

This policy covers three families of dependency, namely the subprocessors that process data on our behalf, the software supply chain (open-source dependencies and container images), and the cloud services we operate. It does not cover our customers, whose commitments are set out in the data processing agreement published on the website.

Principles

  • Reduce the dependency before governing it: nearly all of our infrastructure is self-hosted in datacenters we own, with no hyperscaler. The best supplier risk is the one you do not have.
  • A narrow scope per subprocessor: each subprocessor is confined to a precise function, never granted general access.
  • Contractual framing every time: a data processing agreement for each of them, and standard contractual clauses as soon as a transfer leaves the European Union.
  • Support is never subcontracted: no provider works on customer support, it is handled 100 % in-house.
  • Re-internalisable: our critical components are open source and self-hosted, which makes the infrastructure auditable and reclaimable by the customer.

Measures

AreaMeasure
SubprocessorsA small number of subprocessors, each governed by a data processing agreement (DPA) and, for transfers outside the European Union, by standard contractual clauses (A.5.19).
ScopeStripe is limited to payment processing, Cloudflare to DNS and denial-of-service protection, Better Stack to uptime monitoring; the current list is published on our subprocessors page (A.5.19, A.5.20).
AgreementsSecurity requirements written into subprocessor agreements (A.5.20).
ICT supply chainOpen-source dependencies tracked and updated automatically, version bumps subject to human review, images pulled from an internal registry with pinned tags; a formal software-supply-chain security process to be completed (A.5.21, partial).
Monitoring and reviewOperational monitoring of supplier services in place; a formalised periodic review to be set to a cadence (A.5.22, partial).
Cloud servicesCloud services operated on our own infrastructure, under our control, with no dependency on a hyperscaler (A.5.23).

Two of those subprocessors are US companies. We confine their scope to payment and network protection alone, under standard contractual clauses, and we are evaluating a European alternative to Cloudflare.

Responsibilities

  • The CISO (François-Guillaume Ribreau) owns this policy, the security requirements written into agreements and the monitoring of supplier services.
  • The DPO (Robin Straub) validates the data processing agreement and the transfer safeguards for each subprocessor, and keeps the published list current.
  • Anyone observing abnormal behaviour from a supplier service reports it to [email protected].

Status and roadmap

Contractual framing of subprocessors, security requirements in agreements and control over our cloud services are in place and operational (A.5.19, A.5.20, A.5.23). Two items remain partial and are declared as such. The formal software-supply-chain security process (A.5.21) is carried today by automated dependency tracking and pinned images, and the formalised periodic review of supplier services (A.5.22) is carried today by operational monitoring without a written cadence. Two adjacent technical reinforcements are under way, namely digest pinning with blocking admission for images (A.8.19) and anti-malware image scanning in continuous integration (A.8.7).

Review

This policy is reviewed at least once a year, and whenever a subprocessor is added, removed or has its scope changed.

Last reviewed: 31 August 2026.

See also