Fingerprint: who controls a software vendor's data

Fingerprint: who controls a software vendor's data

Scan any software vendor and see the chain of companies that can reach your data, each tagged with the country whose courts can compel it.
Free, no account needed:  app.moralfabric.org/fingerprint .

Why ownership, not location

"Our data is in an EU datacenter" is the usual answer to a privacy question. What matters is which country's courts can compel the company holding the keys.
  • The US CLOUD Act lets US authorities compel a US company to hand over data it controls, wherever it is stored. An AWS region in Frankfurt is still Amazon.
  • FISA Section 702 lets US intelligence agencies compel US communication providers to hand over data about non-US people.
  • Schrems II is the 2020 EU court ruling that struck down Privacy Shield, precisely because of those powers.
  • The EU-US Data Privacy Framework is the 2023 replacement that makes EU to US transfers lawful. It is a political adequacy decision, it faces legal challenge, and previous versions were annulled twice.
None of this makes US software unusable. It means the choice should be deliberate, and the paperwork should exist.

Run a scan

    Type the vendor's domain, for example moneybird.nl. The https:// is optional.
    Press Scan. Most finish in seconds, occasionally half a minute.
The domain lands in the address bar, so app.moralfabric.org/fingerprint?domain=moneybird.nl re-runs that scan for anyone you send it to. Useful for a procurement thread or a board paper.

What the report shows

Section
What it tells you
Chain of control
The vendor, its hosting, its CDN and its email, layer by layer, with what each layer actually does
The company behind the product
Legal entity, registration and address, read from the vendor's own terms, privacy or imprint pages
Where it runs
The cloud and region proven by public DNS, and the data-residency verdict. Shown after ownership because it is the weaker signal
The app your team logs into
The real product host, often different infrastructure from the marketing site
What the vendor says on paper
The privacy policy, terms and security page. Disagreement with the findings above is the interesting part
Third parties the site loads
Origins declared in the site's own Content-Security-Policy header
Other signals
Mail providers, domain verifications, and detected technology
Every claim shows its evidence. A parent company named in a vendor's own imprint is presented differently from one that is merely recalled.

A worked example

Scan moneybird.nl:
  • Vendor: Moneybird B.V., Netherlands, from their own terms page.
  • Infrastructure: AWS eu-central-1 in Frankfurt, run by Amazon, United States.
  • Company mailbox: Google Workspace, run by Alphabet, United States.
A Dutch company, storing data in Germany, on servers operated by an American one. For most nonprofits that is defensible. The value is knowing it.

What it cannot tell you

Fingerprint reads public DNS records, HTTP headers, and the pages the vendor publishes. It never logs in, and it cannot see your contract.
  • The subprocessor list in a DPA is usually longer than the site's headers suggest.
  • A vendor can run on European infrastructure and still route support tooling or backups elsewhere.
  • Some sites block automated requests. The report says what it could not read.
Treat it as a first pass, not a finished data protection impact assessment.

Use it alongside your supplier records

Fingerprint works on any domain, so you can run it before a vendor comes near your workspace. Once you add them to  Suppliers , the record's Legal Entity fields hold the same detail, and its Auto-fill button reads the same legal pages.
For how Moral Fabric handles your own data, see  Trust & access .

Fair use

Each scan makes real outbound requests, so it is capped at 20 per hour from the same address.

FAQ

Do I need a Moral Fabric account? No.
Does the vendor find out I scanned them? The scan fetches public pages the way any browser does. It does not identify you or your organisation.
Can I scan our own domain? Yes, and it is a good place to start.
Is the result saved to the supplier record? No. Copy the legal entity details across, or press Auto-fill there.
Something looks wrong. Use the feedback tab on the report page. It reaches us with the scanned domain attached.

Related

  •  Connect Moral Fabric to your AI tools 
  • The operations assessment at  app.moralfabric.org/assessment , our other free public tool