Skip to content
DocumentationSecuritySuppliers, subprocessors and data flow
SecurityCurrent contractVersion DOCS-2.0

Suppliers, subprocessors and data flow

How external dependencies should be governed and why a technical provider catalog is not the same as a legal subprocessor register.

How to interpret this document

This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.

External dependencies

Model providers, OAuth connectors, hosting infrastructure and auxiliary services can participate in the data flow depending on the feature being used.

Minimization

The design should send only the data required for the operation. Integration Hub, for example, prioritizes aggregated metrics in the INT-1.0 baseline.

Assessment

Security, Privacy and Procurement should evaluate contractual terms, location, retention, subcontracting and provider controls according to criticality and the data involved.

Public register

The product does not currently claim a complete formal public subprocessor register. Publishing one requires a validated inventory and an ongoing update process.

Provider change

Changing a dependency can affect security, privacy, methodology and comparability. Material changes should be governed rather than treated as a minor implementation detail.