Third-party vendor and subprocessor security requirements.
Vendors that process customer data undergo security assessment proportional to risk before onboarding.
High-risk vendors are reviewed annually. Questionnaires, certifications, and audit reports are evaluated where available.
Contracts include confidentiality, data protection, breach notification, and right-to-audit clauses where appropriate.
Subprocessors are documented. Customers are notified of material subprocessor changes per agreement terms.
Vendor security posture is re-evaluated upon material service changes or reported incidents.