"Our data is in an EU datacenter" is the usual answer to a privacy question. What matters is which country's courts can compel the company holding the keys.
- lets US authorities compel a US company to hand over data it controls, wherever it is stored. An AWS region in Frankfurt is still Amazon.
- lets US intelligence agencies compel US communication providers to hand over data about non-US people.
- is the 2020 EU court ruling that struck down Privacy Shield, precisely because of those powers.
- is the 2023 replacement that makes EU to US transfers lawful. It is a political adequacy decision, it faces legal challenge, and previous versions were annulled twice.
None of this makes US software unusable. It means the choice should be deliberate, and the paperwork should exist.
Type the vendor's domain, for example moneybird.nl. The https:// is optional.
Press . Most finish in seconds, occasionally half a minute.
The domain lands in the address bar, so app.moralfabric.org/fingerprint?domain=moneybird.nl re-runs that scan for anyone you send it to. Useful for a procurement thread or a board paper.
The vendor, its hosting, its CDN and its email, layer by layer, with what each layer actually does
Legal entity, registration and address, read from the vendor's own terms, privacy or imprint pages
The cloud and region proven by public DNS, and the data-residency verdict. Shown after ownership because it is the weaker signal
The real product host, often different infrastructure from the marketing site
The privacy policy, terms and security page. Disagreement with the findings above is the interesting part
Origins declared in the site's own Content-Security-Policy header
Mail providers, domain verifications, and detected technology
Every claim shows its evidence. A parent company named in a vendor's own imprint is presented differently from one that is merely recalled.
Scan moneybird.nl:
- Moneybird B.V., Netherlands, from their own terms page.
- AWS eu-central-1 in Frankfurt, run by Amazon, United States.
- Google Workspace, run by Alphabet, United States.
A Dutch company, storing data in Germany, on servers operated by an American one. For most nonprofits that is defensible. The value is knowing it.
Fingerprint reads public DNS records, HTTP headers, and the pages the vendor publishes. It never logs in, and it cannot see your contract.
- The subprocessor list in a DPA is usually longer than the site's headers suggest.
- A vendor can run on European infrastructure and still route support tooling or backups elsewhere.
- Some sites block automated requests. The report says what it could not read.
Treat it as a first pass, not a finished data protection impact assessment.
Fingerprint works on any domain, so you can run it before a vendor comes near your workspace. Once you add them to Suppliers , the record's fields hold the same detail, and its button reads the same legal pages. Each scan makes real outbound requests, so it is capped at 20 per hour from the same address.
No.
The scan fetches public pages the way any browser does. It does not identify you or your organisation.
Yes, and it is a good place to start.
No. Copy the legal entity details across, or press there.
Use the feedback tab on the report page. It reaches us with the scanned domain attached.