Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Under GDPR and the agreements that copy its language, a controller decides why and how personal data is processed, a processor handles that data on the controller's instructions, and a subprocessor is a vendor the processor brings in to help. If you are a SaaS company, your customer is usually the controller, you are the processor, and every vendor of yours that touches their data is a subprocessor you must disclose.
The practical test is not how important a vendor feels, it is whether customer personal data reaches them. A cheap logging tool that receives request payloads is a subprocessor. An expensive accounting platform that never sees customer data is not.
Keep one inventory with a risk tier per vendor, and let the depth of the assessment follow the tier. A vendor that can reach production data earns a real review; one that cannot earns a record and a signature.
traztech delivers Third-party risk management for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
It comes up the first time a customer sends a data processing agreement and asks for your subprocessor list. Most companies can name their vendors. Far fewer can say which of those vendors is a subprocessor, and the distinction is contractual rather than technical.
It comes up again at audit. SOC 2 asks about vendor risk at CC9.2 and ISO 27001:2022 at A.5.19 through A.5.22, and third-party management is one of the most reliable sources of findings, because it is tedious work with no visible payoff until somebody asks for it.
Whether they process personal data on your behalf as part of delivering your service. Your cloud host, your email provider and your support desk usually are. Your accountant and your office landlord usually are not, because they are not processing your customers' data for you.
Under most data processing agreements, yes, with notice and often a right to object. This is why the list has to be maintained rather than assembled once. Adding a vendor quietly is the version of this that turns into a contractual problem later.
They check that you have a vendor inventory, that it is risk-tiered, that assessments were done in line with your own policy, and that agreements exist where your policy says they should. The list itself is the artefact those tests run against.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.