How we vet them
- Pre-engagement assessment Before engaging any new provider with access to sensitive data or systems, we review their data-handling practices, encryption, access controls, incident response, compliance certifications, and data residency.
- Contractual requirements Contracts include data-protection and confidentiality obligations, security incident notification, audit rights, data return/destruction on termination, and compliance with applicable privacy law.
- Ongoing monitoring Each provider is reviewed annually, covering changes in security posture, new certifications or audit reports, incident history, and continued contractual compliance.
- Change notification Material changes to our subprocessor list are reflected on this page. Enterprise customers can subscribe to a change notification feed.