• Platform
    • Platform overview
    • How it works
    • Cloud Controller
    • Secure NAT gateway
    • GWLB inspection
    • Compliance
  • Landing zones
    • All landing zones
    • AWS landing zones
    • Azure landing zones
    • AWS Marketplace
    • Azure Marketplace
  • Compare
    • All comparisons
    • Versus Azure Firewall
    • Versus AWS Network Firewall
    • NAT gateway alternative
    • Azure Firewall cost
    • AWS NAT Gateway cost
    • Savings calculator
  • Pricing
  • Partners
    • Partner programme
    • MSSP and MSP
    • Resellers
    • White-label firewall
Book a demo Start free
  • Platform

    • Platform overview
    • How it works
    • Cloud Controller
    • Secure NAT gateway
    • GWLB inspection
    • Compliance
    • PCI DSS firewall
    • SOC 2 firewall
    • Firewall audit
    • Articles
  • Landing zones

    • All landing zones
    • AWS landing zones
    • Azure landing zones
    • AWS Marketplace
    • Azure Marketplace
  • Compare

    • All comparisons
    • Versus Azure Firewall
    • Versus AWS Network Firewall
    • NAT gateway alternative
    • Azure Firewall cost
    • AWS NAT Gateway cost
    • Savings calculator
    • Versus alterNAT
    • AWS Network Firewall cost
    • Azure NAT Gateway cost
    • Azure Firewall cost example
    • Google Cloud NGFW cost
  • Pricing
  • Partners

    • Partner programme
    • MSSP and MSP
    • Resellers
    • White-label firewall
Start free Book a demo

Legal · Data Processing Agreement

Data Processing Agreement

Effective 26 August 2026 · Version 1.0 · Last updated 26 August 2026

This Data Processing Agreement (this “DPA”) is a standalone document incorporated into and forming part of the Software Licence Agreement by reference. It is drafted that way deliberately: the self-serve customer base accepts the Licence at checkout and never sees an Order Form, so processor terms that lived only in a negotiated Order would cover a minority of the customers who need them.

At a glance

This summary is for convenience only. It is not operative and creates no rights or obligations — see clause 1.4.

What it is The Article 28 terms on which Enforza processes personal data on your behalf
Where your data lives AWS London (eu-west-2) only. Enforza operates no other production region
Does your traffic reach us No. Customer traffic never transits Enforza's cloud. Firewall logs are written on your own machine and shipped to your own SIEM
What about the live-log viewer Log lines are relayed, not stored — held in memory for the seconds they are on the wire, never written to an Enforza database, and the relay times itself out after 15 minutes
Do you decrypt our TLS Never. Enforza reads TLS metadata off the clear-text wire (SNI, ALPN, JA3/JA3S). No payload content is processed at any point
Sub-processors Three today — AWS, Stripe and Google Workspace. Published at Annex 3 and in the standing register; 30 days' notice of any addition, with a right to object
Security Annex 2. Customer-managed KMS encryption on every store, point-in-time recovery, CI-only deployment with no static cloud credentials, no inbound management ports
Breach Notified to you without undue delay and within 24 hours of Enforza becoming aware
On exit Deletion within 30 days of the end of the Licence, or return first if you ask within 30 days

Parties

Enforza — Synvu Limited, trading as Enforza, registered in England and Wales under company number 15761962, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom (“Enforza”).

Customer — the Licensee under the Licence, or where this DPA is entered into as a separately signed agreement, the entity identified in that signed agreement (“Customer”).

Contents

  1. 1. Structure and interpretation
  2. 2. Definitions and roles
  3. 3. Enforza's obligations
  4. 4. The Customer's obligations
  5. 5. Sub-processors
  6. 6. International transfers
  7. 7. Security
  8. 8. Personal data breach
  9. 9. Data subject requests
  10. 10. Data protection impact assessments
  11. 11. Audit and information
  12. 12. Deletion and return
  13. 13. Liability
  14. 14. General
  15. Part B — Where the Customer is a Partner
  16. Annex 1 — Description of the processing
  17. Annex 2 — Technical and organisational measures
  18. Annex 3 — Sub-processors
  19. Annex 4 — International transfers
  20. Annex 5 — South Africa (POPIA)

1. Structure and interpretation

1.1 This DPA is incorporated into and forms part of the Software Licence Agreement between Enforza and the Customer (the “Licence”), and where the Customer is a partner, into the Partner Terms between them. Terms defined in the Licence have the same meaning here unless defined differently in clause 2.

1.2 Precedence. In the event of conflict, the order of precedence is: (1) this DPA, in respect of the processing of Customer Personal Data; (2) any Order Form; (3) the Licence; (4) the Service Level Agreement. This DPA prevails over the Licence to the extent of any conflict about data protection, and nothing in the Licence or the SLA varies it.

1.3 No termination independent of the Licence. This DPA continues for as long as Enforza processes Customer Personal Data and terminates when the deletion obligation in clause 12 has been discharged.

1.4 The At a glance table above is a summary for convenience. It is not operative and creates no rights or obligations.

2. Definitions and roles

2.1 Definitions.

TermMeaning
Data Protection LawThe UK GDPR and the Data Protection Act 2018; and, where the Customer is established in the EEA or the processing is subject to it, Regulation (EU) 2016/679 and applicable member-state law. Where Annex 5 applies, the Protection of Personal Information Act 2013 (South Africa)
Customer Personal DataPersonal data described in Annex 1 that Enforza processes on the Customer's behalf under the Licence
Account DataPersonal data relating to the Customer's own commercial relationship with Enforza — the account holder's identity, billing and transaction records, and marketing preferences. See clause 2.4
Sub-processorAny processor engaged by Enforza to process Customer Personal Data
Restricted TransferA transfer of personal data to a country not covered by UK (or, as applicable, EU) adequacy regulations, for which an Article 46 safeguard is required
Controller, processor, personal data, processing, personal data breach, data subjectAs defined in Data Protection Law

2.2 Roles. For Customer Personal Data, the Customer is the controller and Enforza is the processor. Where the Customer is itself a processor for a third party, clause 2.5 and Part B apply.

2.3 Enforza processes only on documented instructions. The Licence, this DPA, each Order Form and the Customer's own use of the consoles, APIs and CLI together constitute the Customer's documented instructions. Enforza shall not process Customer Personal Data for any other purpose, and shall inform the Customer if it considers an instruction infringes Data Protection Law.

2.4 Enforza is a controller for Account Data, and this DPA does not cover it. Enforza determines the purposes and means of processing the account holder's identity, billing records and marketing preferences, and does so under its own privacy notice at enforza.io/privacy-policy. The two roles can attach to the same individual — a named administrator is both an account contact (controller processing) and a console user whose access logs Enforza holds for the Customer (processor processing). Where the same personal data is processed in both capacities, this DPA governs the processor capacity only.

2.5 Where the Customer is a partner. Where the Customer holds Partner Terms and sub-licenses the platform to its own clients, Part B applies in addition to this Part A, and the Customer is a processor and Enforza a sub-processor in respect of that client's personal data.

3. Enforza's obligations

3.1 Enforza shall:

  1. process Customer Personal Data only on the Customer's documented instructions (clause 2.3), and only for the duration and purposes set out in Annex 1;
  2. ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality that survives the end of their engagement;
  3. implement and maintain the technical and organisational measures set out in Annex 2, and not materially degrade them during the term;
  4. respect the conditions in clause 5 for engaging a Sub-processor;
  5. assist the Customer as set out in clauses 8, 9 and 10;
  6. delete or return Customer Personal Data as set out in clause 12; and
  7. make available the information described in clause 11.

3.2 No use of Customer Personal Data for Enforza's own purposes, including product development, model training or benchmarking, except as expressly permitted by clause 3.3.

3.3 Aggregation and anonymisation. Clause 2.8 of the Licence permits Enforza to use Licensee Data in an anonymous and aggregated form to improve the platform. The Customer instructs Enforza to carry out that anonymisation as a processing operation under this DPA. Enforza shall:

  1. anonymise irreversibly, so that no data subject is identifiable by Enforza or by any other person by any means reasonably likely to be used, applying the standard for anonymisation in Data Protection Law and current ICO guidance;
  2. not attempt to re-identify, or permit any third party to re-identify, any data subject from the resulting data;
  3. not include in the resulting data any IP address, hostname, FQDN, cloud account identifier, instance identifier or engine fingerprint, whether alone or in combination, from which an individual or a single Customer could be distinguished; and
  4. treat the output as anonymous information outside the scope of Data Protection Law only once (1) to (3) are satisfied.

Nothing in Licence clause 2.8 authorises the use of pseudonymised data, or of data from which a single Customer's estate is distinguishable, as if it were anonymous.

3.4 No TLS decryption. Enforza does not decrypt, intercept or process the content of the Customer's network traffic at any point. The engine reads unencrypted TLS handshake metadata only.

3.5 Traffic log data is relayed, not stored. Where the Customer opens the in-console live-log viewer, the Customer instructs Enforza to relay traffic log entries from the Customer's engine to the Customer's browser over Enforza's WebSocket infrastructure. Enforza shall not write those entries to persistent storage, and the relay terminates automatically after 15 minutes of inactivity.

This clause concerns the source IP addresses contained in the Customer's firewall traffic logs only. Separately, and in its capacity as a controller (clause 2.4), Enforza retains certain IP addresses that are not Customer Personal Data — namely website-visitor IP addresses, for site monitoring and analytics, and sign-up and payment IP addresses, for fraud prevention on account creation and payment. That controller-side processing is governed by Enforza's Privacy Policy, not by this DPA.

4. The Customer's obligations

4.1 The Customer warrants that it has, and will maintain, a lawful basis for the processing it instructs, and that it has provided all information required by Articles 13 and 14 to the data subjects concerned.

4.2 The Customer controls what enters the platform. Firewall policy is authored by the Customer, in its own repository or in the console. The Customer shall not include in policy content, object names, comments or support correspondence any special category data within Article 9, criminal offence data within Article 10, or any personal data that is not necessary for the operation of the service.

4.3 The Customer is responsible for configuring log export to its own SIEM, for the security of the machines on which it runs the engine, and for the management of its own console users, roles and credentials.

5. Sub-processors

5.1 General written authorisation. The Customer gives Enforza general written authorisation to engage Sub-processors. Those engaged at the date of this DPA are listed at Annex 3 and maintained in the standing register published at enforza.io/sub-processors.

5.2 Notice and objection. Enforza shall give the Customer at least 30 days' notice, by email to the Customer's notice address and by updating the register, before a new Sub-processor begins processing Customer Personal Data. Notice by updating the register alone is not sufficient. The Customer may object on reasonable data-protection grounds within that period, in which case the parties shall discuss in good faith; if no resolution is reached within 30 days of the objection, the Customer may terminate the Licence on written notice, without liability, with a pro-rata refund of any fee paid for the unexpired term.

5.3 Flow-down and responsibility. Enforza shall impose on each Sub-processor data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the acts and omissions of its Sub-processors as if they were its own.

5.4 Emergency substitution. Where a Sub-processor must be replaced at short notice to preserve the security or continuity of the service, Enforza may do so with as much notice as is practicable, and shall notify the Customer without undue delay. Clause 5.2's objection right applies from the date of that notice.

6. International transfers

6.1 Hosting is UK-only. Enforza processes and stores Customer Personal Data in the AWS eu-west-2 (London) region. Enforza operates no other production region and shall not move Customer Personal Data to another region without the Customer's prior written agreement and an appropriate transfer mechanism.

6.2 Where transfers nonetheless arise. A Restricted Transfer may occur in the circumstances listed at Annex 4 — content delivery through a global edge network, payment processing, and support access by a partner or by Enforza personnel outside the UK. For each, Enforza shall ensure a valid Article 46 safeguard is in place before the transfer occurs.

6.3 Mechanism. Where a Restricted Transfer is made under this DPA, the parties enter into the IDTA or the EU SCCs as amended by the UK Addendum, as applicable, incorporated by reference and completed as set out at Annex 4. In the event of conflict between that instrument and this DPA, the instrument prevails.

6.4 Transfer risk assessment. Enforza shall carry out and keep under review a transfer risk assessment for each Restricted Transfer, and shall make it available to the Customer on request under clause 11.

7. Security

7.1 Enforza shall implement and maintain the technical and organisational measures described in Annex 2, appropriate to the risk, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing.

7.2 Enforza may update the measures in Annex 2 provided the level of protection is not materially reduced. Material reductions require the Customer's prior written agreement.

7.3 Enforza does not hold SOC 2, ISO 27001 or any equivalent third-party security certification. Annex 2 is a description of the measures actually in place, given in place of certification, and the Customer acknowledges it has been told so before entering into this DPA.

8. Personal data breach

8.1 Enforza shall notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within 24 hours of becoming aware of it.

8.2 The notification shall describe, so far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Enforza shall provide further information as it becomes available rather than delay the initial notification to complete it.

8.3 Enforza shall assist the Customer with its own obligations under Articles 33 and 34, including any notification to a supervisory authority or to data subjects.

8.4 Enforza shall not notify a supervisory authority or any data subject on the Customer's behalf unless required by law or instructed in writing by the Customer, and shall not make any public statement identifying the Customer without the Customer's prior written agreement, save where required by law.

8.5 Notification of a breach is not an admission of fault or liability.

9. Data subject requests

9.1 Enforza shall notify the Customer without undue delay, and in any event within 2 Business Days, if it receives a request from a data subject exercising rights under Articles 15 to 22 in respect of Customer Personal Data, and shall not respond to it itself except to direct the data subject to the Customer.

9.2 Taking into account the nature of the processing, Enforza shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling such requests. The consoles provide the Customer with direct access to, correction of and deletion of its own user records and configuration, and the Customer shall use those facilities in the first instance.

9.3 Enforza may charge a reasonable fee for assistance that goes materially beyond what the consoles provide, having first given the Customer a written estimate and obtained its agreement.

10. Data protection impact assessments

10.1 Enforza shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the nature of the processing and the information available to Enforza. Clause 9.3 applies to that assistance.

11. Audit and information

11.1 Enforza shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 and this DPA, including Annex 2, the current sub-processor register, and any transfer risk assessment.

11.2 Information first. The Customer shall accept the information provided under clause 11.1, together with any security questionnaire response and any third-party audit report Enforza holds, in satisfaction of its audit right where those materials reasonably address the matter in question.

11.3 Audit. Where they do not, the Customer may audit, or appoint an independent auditor to audit, Enforza's processing, subject to: not more than once in any 12-month period except following a personal data breach or a supervisory authority's requirement; at least 30 days' written notice; during UK business hours; without unreasonable disruption; subject to confidentiality undertakings; and at the Customer's cost, save where the audit identifies a material breach of this DPA by Enforza, in which case Enforza bears its own and the Customer's reasonable costs.

11.4 An auditor who is a competitor of Enforza may be refused, provided Enforza proposes an alternative acceptable to the Customer acting reasonably.

11.5 Enforza is a very small company. The parties acknowledge that clauses 11.2 to 11.4 are calibrated to that fact, and that an unrestricted on-site audit right would be disproportionate to the risk of the processing described in Annex 1.

12. Deletion and return

12.1 On the end of the Licence, Enforza shall, at the Customer's election, delete or return Customer Personal Data and delete existing copies.

12.2 The Customer must make that election within 30 days of the end of the Licence. If it does not, Enforza shall delete.

12.3 Enforza shall complete deletion within 30 days of the election or of the expiry of the election period, whichever is earlier, save that:

  1. data held in encrypted backups and point-in-time recovery snapshots is deleted on the expiry of the applicable backup cycle, which does not exceed 35 days, and remains subject to this DPA until it is; and
  2. Enforza may retain Customer Personal Data to the extent required by law, including billing and transaction records retained under clause 12.4.

12.4 Records Enforza must keep. Enforza retains billing and transaction records for 6 years from the end of the relevant financial year, as required by the Companies Act 2006 and by HMRC. Those records are Account Data under clause 2.4 and are not deleted under this clause.

12.5 Enforza shall confirm deletion in writing on request.

13. Liability

13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Licence or, where applicable, the Partner Terms, save that nothing in this DPA or in those agreements limits or excludes either party's liability to a data subject, or any liability that cannot lawfully be limited.

13.2 Liability under this DPA counts toward, and is not in addition to, the aggregate liability cap in the Licence or, where applicable, the Partner Terms. That cap applies to all claims arising out of or in connection with this DPA taken together with all claims under the agreement it is incorporated into.

13.2A Clause 13.2 is subject to clause 13.1, and accordingly does not limit or exclude:

  1. either party's liability to a data subject, including under Article 82;
  2. any administrative fine or other sanction imposed on a party by a supervisory authority, which is not a matter the parties can allocate between themselves; or
  3. any other liability that cannot lawfully be limited.

13.3 Where both parties are liable to a data subject or to a supervisory authority for the same damage, each shall bear its share determined by reference to its responsibility for the damage, and each shall provide the other with reasonable assistance in establishing that share.

14. General

14.1 Variation. This DPA may be varied only in writing. Where variation is required by a change in Data Protection Law or by the adoption of a new transfer mechanism, the parties shall negotiate in good faith to agree it promptly.

Notwithstanding clause 12.1 of the Licence, Enforza may not vary this DPA by notice, by posting on its website, or by any mechanism relying on the Customer's continued use of the platform as acceptance.

14.2 Governing law. This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where a transfer instrument incorporated under clause 6.3 requires otherwise for the purposes of that instrument.

14.3 Contact. Data protection matters may be raised with Enforza at contact@enforza.io.

14.4 No data protection officer. Enforza has assessed that it is not required to appoint a data protection officer under Article 37, and has not appointed one. The contact at clause 14.3 is the responsible point of contact.

Part B — Where the Customer is a Partner

This Part applies in addition to Part A wherever the Customer holds Partner Terms and sub-licenses the platform to its own clients.

B1. The chain

B1.1 In respect of personal data of a Client of the Partner, or of that Client's own personnel or end users:

  • the Client is the controller;
  • the Partner is a processor acting on the Client's documented instructions; and
  • Enforza is a sub-processor engaged by the Partner.

B1.2 The Partner warrants that it has the Client's authorisation — general or specific — to engage Enforza as a sub-processor, and that it has given the Client any notice and objection right its own agreement with the Client requires.

B1.3 The Partner shall impose on the Client, and the Client shall be bound by, terms no less protective than Part A, and shall procure that the Client's instructions do not require Enforza to act inconsistently with Part A.

B2. Flow-down of Part A

B2.1 Part A applies as between Enforza and the Partner as if references to the “Customer” were references to the Partner, and as if references to the “Customer's documented instructions” were references to instructions the Partner is authorised by the Client to give.

B2.2 Enforza owes its Article 28 obligations to the Partner, not directly to the Client, save where clause B3 applies.

B3. Direct engagement on termination

B3.1 Where Enforza exercises the step-in right at clause 11.4 of the Partner Terms and contracts directly with a Client, Enforza becomes that Client's processor from the date of the direct contract, and Part A applies between them from that date.

B3.2 During the Transition Period, and for the sole purpose of maintaining service continuity for the Client, the Partner instructs Enforza to continue processing on the instructions last given. That instruction survives termination of the Partner Terms for the duration of the Transition Period.

B4. Breach and requests through the chain

B4.1 Enforza notifies the Partner under clause 8.1. The Partner is responsible for onward notification to the Client within the time its own agreement with the Client requires, and shall not delay it pending further information from Enforza.

B4.2 Where a Client contacts Enforza directly about a breach or a data subject request, Enforza shall refer it to the Partner and notify the Partner without undue delay — save where the Partner has failed to respond within 2 Business Days, in which case Enforza may respond to the Client directly to the minimum extent necessary and shall tell the Partner it has done so.

B5. White-labelling

B5.1 Where the Partner white-labels the platform, the Client may not know Enforza is involved. The Partner shall nonetheless name Enforza as a sub-processor in its own sub-processor disclosures to the Client, and warrants that it does. A white-label arrangement does not entitle the Partner to conceal the identity of a sub-processor from a controller.

Annex 1 — Description of the processing

Article 28(3) requires the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject.

1. Subject matter, nature and purpose

Provision of the Enforza cloud-managed firewall and secure NAT gateway platform: account and identity management, firewall policy authoring, validation and distribution, engine registration and licensing, live-log relay, audit logging, and support.

2. Duration

For the term of the Licence, and thereafter only as permitted by clause 12.

3. Frequency

Continuous, for the duration of the Licence.

4. Categories of data subject

CategoryNotes
The Customer's personnel who hold console, API or CLI accountsAdministrators, operators, viewers
Individuals invited to the Customer's tenant but not yet enrolledInvitation records
The Customer's own personnel and end users whose network traffic traverses an engineIdentifiable only by network identifier — see §5
Where Part B applies, the equivalent categories for the Partner's Client

5. Categories of personal data

CategoryDetailWhere
Identity and accountName, email address, given/family name, profile picture URL, role, invited-by, Cognito subject identifier, tenant identifierAmazon Cognito; the Enforza tenant datastore
Authentication credentialsPassword hash, TOTP secret, refresh tokensAmazon Cognito only. Not present in any Enforza-operated database
Federated identitySubject identifier and email from Google, Microsoft or GitHub where the Customer uses SSOCognito; OIDC façade codes (~30 second lifetime)
Access and security logsIP address, login timestamp, session metadata, audit events recording who did what and whenEnforza audit-event store; AWS platform logs
Host and cloud metadataHostname, OS version, cloud provider, cloud account or subscription identifier, instance identifier, region, engine fingerprintEnforza tenant and firewall-claim stores
Policy configurationFirewall rules and object libraries, which may contain IP addresses, CIDR ranges, hostnames and FQDNs, and free-text rule comments authored by the CustomerEnforza policy and object-library stores; or the Customer's own git repository
Traffic log entriesSource and destination IP and port, protocol, matched rule, verdict, and TLS handshake metadata (SNI, ALPN, JA3/JA3S), contained in the Customer's firewall traffic logsRelayed in memory only. Not stored by Enforza. Written to a local log file on the Customer's own machine and shipped to the Customer's own SIEM
LicensingShort-lived PASETO tokens and registration keys bound to an engineEnforza licence-token store
Support correspondenceContact details and whatever the Customer chooses to includeEnforza mailbox — see Annex 3

No special category data within Article 9 and no criminal offence data within Article 10 is processed by design. Enforza performs no TLS decryption, so no communications content is processed at any point. Clause 4.2 places the corresponding obligation on the Customer.

The “relayed in memory only, not stored by Enforza” position in the Traffic log entries row concerns the source IP addresses in the Customer's firewall traffic logs. It does not describe the IP addresses that Enforza retains as a controller — website-visitor IPs for monitoring and analytics, and sign-up and payment IPs for fraud prevention — which fall outside this DPA and are governed by the Privacy Policy (clauses 2.4 and 3.5).

6. Retention

StoreRetention
Tenant store (company, user, engine, binding records)Life of the account, then deleted under clause 12
Audit-event store13 months
Licence-token storeAutomatic expiry at token expiry
SSO code storeApproximately 30 seconds
Billing-event store7 days
Policy, object-library and firewall-claim storesLife of the account
Amazon Cognito user poolLife of the account
Traffic log entriesNot retained by Enforza. Transient relay; the relay self-terminates after 15 minutes of inactivity
Point-in-time recovery snapshots and backups35 days rolling (DynamoDB PITR)
Billing and transaction records6 years (Account Data — clause 12.4)

7. Location

AWS eu-west-2 (London), United Kingdom. See Annex 4 for the limited circumstances in which data leaves that region.

Annex 2 — Technical and organisational measures

Given in place of a third-party certification. Enforza holds none — clause 7.3.

1. Encryption

  • Every DynamoDB table is encrypted at rest with a customer-managed KMS key under Enforza's control, not an AWS-owned default key.
  • All data in transit is protected by TLS. The engine's only channel to the cloud is a TLS-protected WebSocket.
  • Engine licence tokens are signed with an ECC NIST P-256 key held in KMS; the OIDC façade signs with a separate RSA-2048 KMS key. Private key material never leaves KMS — signing is performed by the KMS service.

2. Access control and authentication

  • Console authentication is Amazon Cognito, with email as the login identifier and TOTP multi-factor authentication available.
  • Optional single sign-on via Google, Microsoft and GitHub, the latter two through self-hosted OIDC façades so that Cognito receives a stable issuer.
  • Tenant isolation is enforced at the authorisation layer: the tenant identifier is carried as a Cognito custom claim and read from the signed JWT on every request, not supplied by the caller.
  • Every WebSocket connection, engine and browser alike, passes a Lambda authorizer that verifies signature, audience, issuer and expiry.
  • Engines authenticate with short-lived PASETO tokens re-issued on each heartbeat, with a revocation list published for immediate invalidation.
  • Cross-account clone detection — engine fingerprints are indexed so that the same engine identity appearing in two accounts is detected.

3. Network architecture

  • The engine holds one outbound WebSocket and accepts no inbound connections. No management port is exposed on any customer machine.
  • Customer traffic never transits Enforza's infrastructure. Filtering happens on the Customer's own machine, in the Customer's own cloud account.
  • No TLS decryption at any point. Only clear-text handshake metadata is read.
  • The engine holds no GitHub credentials; policy is fetched server-side and returned inline.

4. Separation of environments

  • Development and production run in two fully isolated AWS accounts with zero cross-account dependencies and separate Terraform state. The only touchpoint is a one-time DNS delegation.
  • Production personal data is not used in development or testing.

5. Change management and deployment

  • Deployment is CI-only. There are no static AWS access keys; CI authenticates by GitHub OIDC with short-lived credentials.
  • Production deployment is gated on explicit human reviewer approval in the deployment pipeline.
  • Infrastructure is defined as code and version-controlled.

6. Resilience and recovery

  • Point-in-time recovery is enabled on every DynamoDB table.
  • Serverless architecture across multiple availability zones within eu-west-2.
  • An availability monitor is operated from a separate AWS region so that a regional failure does not disable the observer.
  • Point-in-time recovery provides a rolling 35-day window on every table. Restore exercises are not performed on a stated schedule — see §11.

7. Logging and monitoring

  • An append-only audit event log records tenant-scoped administrative actions.
  • AWS platform logging across the compute, gateway and storage layers.

8. Policy compliance tooling

  • Policies are validated before publication against an OPA-backed guardrails service carrying 25 bundled policy packs and 210 controls spanning CIS v8, PCI-DSS v4, ISO 27001, NIST 800-53/171 and CSF 2.0, HIPAA, SOC 2, FedRAMP, CMMC L2, DORA, NIS2, UK Cyber Essentials and others. This is a product control serving the Customer's own compliance, not a certification of Enforza.

9. Personnel

  • Enforza is a small company. All personnel are bound by written confidentiality obligations surviving the end of their engagement.
  • Background screening is carried out on all personnel before they are given access to production systems or to Customer Personal Data.
  • Access to production is limited to those who require it and is exercised through the CI pipeline in preference to direct console access.

10. Security assessment and vulnerability management

  • Recurring adversarial security assessment of the source code. Enforza operates a standing programme of offensive security review across the engine, the serverless control plane, the Terraform and IAM configuration, and the console applications. Assessments to date: 2026-05-08 (full-stack, and a second covering Terraform/IAM, CloudFront, DynamoDB, Cognito and the React console), 2026-05-09 (engine packet processing and policy evaluation) and 2026-08-06 (the engine and its sidecar daemons, reviewed across multiple partitioned attack surfaces against a well-resourced threat model, with every critical and high-severity claim independently verified before acceptance).
  • Findings are tracked to closure in a maintained index. As at 2026-08-25: 22 findings recorded — 21 fixed and verified, 1 formally risk-accepted, 0 open.
  • These assessments are performed by automated security agents against source code, not by an independent third-party penetration testing firm. See §11.
  • Dependencies and infrastructure configuration are version-controlled and reviewed as part of the same programme.

11. Measures Enforza does not have

Stated expressly, because a controller's due diligence is entitled to it and silence would be misleading.

  • No SOC 2, ISO 27001, Cyber Essentials or equivalent third-party certification.
  • No independent third-party penetration test. The assessment programme at §10 is real, recurring and evidenced, but it is conducted by automated agents with source access rather than commissioned from an external testing firm, and it is not a substitute for one. Enforza does not describe it as a penetration test.
  • No stated schedule for backup restore testing. Point-in-time recovery is enabled on every table with a rolling 35-day window; Enforza does not currently perform restore exercises on a defined cycle.
  • No data protection officer (clause 14.4).

Annex 3 — Sub-processors

Current as at 26 August 2026. The standing register is maintained at enforza.io/sub-processors. Clause 5.2 governs changes.

Sub-processorEntity and countryServiceDataLocation of processing
Amazon Web ServicesAWS EMEA SARL, LuxembourgAll hosting, compute, storage, identity, key management and content deliveryAll categories in Annex 1 §5UK (eu-west-2, London) for storage and compute. Content delivery via CloudFront global edge locations — see Annex 4
StripeStripe Payments Europe, Ltd (Ireland) / Stripe, Inc. (USA)Payment processing and subscription billingBilling contact and transaction dataIreland and United States
Google (Google Workspace)Google LLC, United StatesBusiness email and collaboration — hosts support@, escalations@ and contact@enforza.ioSupport correspondence and whatever the Customer includes in it; contact detailsUnited States — see Annex 4 route T4

Not sub-processors, and why

Included so that a reviewer does not have to work it out, and so that the register is not padded with entities that do not process Customer Personal Data.

PartyWhy not
Google, Microsoft, GitHub (as SSO identity providers)Each is the Customer's own identity provider, chosen and controlled by the Customer. Enforza receives an assertion from them; it sends them no Customer Personal Data to process on its behalf
GitHub (as the GPI policy source)The repository is the Customer's own. Enforza reads from it on the Customer's instruction using an installation the Customer grants
Google Analytics, Microsoft Clarity, Google Ads, Microsoft UETMarketing website only. These process visitor data for which Synvu Limited is a controller under its own privacy notice, on consent. They receive no Customer Personal Data and have no access to the platform
The Customer's SIEMThe Customer's own destination, reached by the Customer's own log shipper

Annex 4 — International transfers

1. The default position

Storage and compute are in the UK. On the ordinary operation of the platform there is no Restricted Transfer. This annex exists because three narrow routes out of the UK do exist, and a DPA that did not name them would be inaccurate.

2. The routes

#RouteDataAssessment
T1CloudFront edge delivery. Console static assets and engine downloads are served from a global edge network; the associated certificate and distribution control plane sits in us-east-1Request metadata including source IP address. No account, policy or traffic-log dataA Restricted Transfer of a limited category. Covered by the AWS Data Privacy Framework commitments and its SCC-based addendum
T2Stripe payment processingBilling contact and transaction dataLargely Account Data under clause 2.4, for which Enforza is a controller. To the extent any is Customer Personal Data, covered by Stripe's own transfer terms
T3Support access from outside the UK. A Partner in India, Malaysia, Singapore, South Africa or the UAE holding first-line support, and any Enforza personnel working outside the UKWhatever the support matter requires — potentially any Annex 1 categoryA Restricted Transfer. Covered by the transfer mechanism at §4, completed per country
T4Google Workspace. Support correspondence held in Enforza's mailboxesContact details and whatever a Customer puts in a support email — potentially any Annex 1 categoryA Restricted Transfer to the United States. Covered by Google's Cloud Data Processing Addendum, which incorporates the Standard Contractual Clauses

3. Direction of travel

A partner sending Enforza a referral or a support ticket is an import into the UK. That is not a Restricted Transfer and needs no safeguard. Enforza sending data back — referral status under a Partner agreement, or giving an overseas partner console access to a shared tenant — is the export, and it is the leg that needs the safeguard.

4. Mechanism

The IDTA (version B1.0), or the EU SCCs with the UK Addendum, as applicable, with:

  • Module: Module Two (controller to processor) or Module Three (processor to sub-processor), as applicable
  • Exporter: Synvu Limited
  • Importer: [PARTNER NAME AND COUNTRY]
  • Annexes: Annex 1 and Annex 2 of this DPA apply
  • Transfer risk assessment: completed per country

None of India, Malaysia, Singapore, South Africa or the UAE holds a UK adequacy decision. All five appear in Enforza's current partner pipeline.

Annex 5 — South Africa: operator terms (POPIA)

Applies only where the Customer, or a Partner's Client, is a responsible party subject to the Protection of Personal Information Act 2013.

A5.1 Enforza acts as an operator for the Customer as responsible party, and processes personal information only with the Customer's knowledge or authorisation.

A5.2 Enforza shall treat personal information as confidential and shall not disclose it unless required by law or in the proper performance of its duties.

A5.3 Enforza shall secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures — those at Annex 2 — as required by section 19.

A5.4 Section 21(2). Enforza shall notify the Customer immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person. Clause 8's 24-hour commitment applies in addition and does not qualify this.

A5.5 Section 72 transfers. The Customer acknowledges that Enforza processes in the United Kingdom, and that this DPA together with the measures at Annex 2 constitutes the binding arrangement required by section 72(1)(a).


Enforza is a product and trading name of Synvu Limited, a company registered in England & Wales (Company No. 15761962), with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Data protection questions about this DPA can be sent to contact@enforza.io.

← Back to home · Privacy Policy · Sub-processors · Terms of Service

The built-for-cloud firewall — same capability as the cloud-native one, at 60–80% less. Flat, per firewall, no per-GB data-processing tax.

Runs on any cloud.

Product

  • Platform
  • Cloud Controller
  • How it works
  • Landing zones
  • AWS landing zones
  • Azure landing zones
  • Secure NAT gateway
  • NAT gateway alternative
  • AWS GWLB Inspection
  • DigitalOcean egress filtering
  • Hetzner Cloud egress firewall
  • AWS Marketplace
  • Azure Marketplace

Compliance

  • Compliance hub
  • PCI DSS firewall
  • SOC 2 firewall
  • HIPAA firewall
  • ISO 27001 firewall
  • NIST firewall rules
  • Firewall audit

Compare

  • All comparisons
  • vs AWS Network Firewall
  • vs Azure Firewall
  • vs Google Cloud NGFW
  • vs OCI Network Firewall
  • vs pfSense
  • vs OPNsense
  • vs fck-nat
  • vs alterNAT
  • vs Aviatrix
  • vs Cisco Multicloud Defense

Pricing

  • Pricing
  • Savings calculator
  • AWS Network Firewall cost
  • Azure Firewall cost
  • Azure Firewall cost example
  • AWS NAT Gateway cost
  • Azure NAT Gateway cost
  • Google Cloud NAT cost
  • Google Cloud NGFW cost

Partners

  • Partner program
  • Reseller program
  • MSSP / MSP platform
  • White-label firewall
  • Multi-tenant firewall

Company

  • About
  • Contact
  • Articles

© 2026 Synvu Limited. All rights reserved.

  • Terms of Service
  • Privacy Policy
  • DPA
  • Sub-processors

Enforza is a trading name of Synvu Limited, a company registered (15761962) in the United Kingdom. Registered office address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

AWS and the “Powered by AWS” / AWS Marketplace logos are trademarks of Amazon.com, Inc. or its affiliates. Microsoft, Azure and the Azure logo are trademarks of the Microsoft group of companies. Google Cloud and all other product and company names, logos and trademarks referenced on this site are the property of their respective owners. Enforza is an independent product and is not affiliated with, endorsed by, sponsored by, or otherwise associated with Amazon Web Services, Microsoft, Google, or any other company mentioned here. All third-party names and marks are used solely for identification and comparison purposes.

We use cookies to measure traffic and, with your consent, support advertising — both stay off until you allow them. See our Privacy & Cookie Policy.