ContraForce
GDPR evidence
Security Delivery Platform to orchestrate AI agents for Service…
ContraForce and GDPR
CertReports found no public GDPR evidence for ContraForce as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 20 Aug 2025
- Expires or valid through
- 18 Aug 2027
- Scope
- ContraForce Group, Inc. operates a Security Service Delivery Platform used by Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and enterprise clients to deliver Managed Detection and Response (MDR) services. Personal data is processed to operate, deliver, and support that platform. We operate on a principle of data minimization and collect only personal data necessary for core business and operational functions. PLATFORM DATA. Customers authenticate through their own Microsoft Entra ID tenants using Single Sign-On. ContraForce does not collect, store, or process authentication credentials; Microsoft handles identity and access management. ContraForce receives identity attributes from customer directories, which may include given name, surname, email address, job title, telephone number, business address, and organizational structure. The platform ingests security telemetry from customer security tools, including Microsoft Sentinel, Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, and other security information and event management and endpoint detection and response products. This telemetry may include personal data such as user names, email addresses, IP addresses, device identifiers, file names, file contents, and email metadata and message content, including subject lines, sender and recipient addresses, and message bodies. Because this telemetry is generated by customer security tooling rather than selected by ContraForce, it may incidentally contain sensitive personal data. ContraForce does not seek such data, processes it only to deliver security detection and response services, and does not use it for any secondary purpose. ContraForce processes all platform data solely on documented instructions from the customer. Where customers are service providers, platform data may relate to their clients' users as well as their own personnel. BUSINESS DATA. ContraForce collects business contact and billing information, including company name, contact name, email address, telephone number, and billing address, for account setup, invoicing, contract management, and support communications. HUMAN RESOURCES DATA. ContraForce processes personal data about current and former employees, contractors, and job applicants, including names, email addresses, and employment records, for human resources administration, payroll, access provisioning, and compliance with labor and tax law. Human resources data is covered under the UK Extension to the EU-U.S. DPF only. ONWARD TRANSFERS. Platform data is hosted on Microsoft Azure as a sub-processor. Notification and alerting emails to platform users are delivered through Brevo. Customer support requests are handled through Atlassian, which may receive personal data included by customers in support tickets. Payment processing is handled through Stripe. Human resources data may be shared with payroll, human resources, and benefits providers. All such providers are contractually bound to process personal data securely, confidentially, and only for specified purposes. ContraForce's current sub-processor list is published at https://trust.contraforce.com/subprocessors. ContraForce does not sell or rent personal data. In limited cases, ContraForce may be required to disclose personal data to regulatory authorities or law enforcement in compliance with legal obligations. SECURITY AND RETENTION. All personal data is encrypted in transit and at rest, with role-based access restricted to necessity. ContraForce does not currently anonymize data. Data is retained only as long as necessary to fulfill the purpose for which it was collected or to meet legal or regulatory requirements. INDIVIDUAL RIGHTS. Requests for access, correction, or deletion may be submitted to [email protected]. ContraForce aims to respond within 30 days.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | ContraForce: Active: EU-US Certification, UK Extension Certification | Live pagesha256 d7aa6aef53 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is ContraForce GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.