Sub-processor Vendor Risk & Access Control Review
Audit Data Processing Addendums (DPAs), HIPAA Business Associate Agreements (BAAs), SOC 2 compliance certificates, and quarterly access recertifications.
Sub-processor Vendor Compliance Ledger
Audit DPAs, BAAs, SOC 2 reports, and data residency regions with browser local storage retention.
| Sub-processor Vendor | Category | Agreements | BAA/DPA Executed | SOC 2 Verified | Residency Region | Audit Status |
|---|---|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Infra & KMS | HIPAA BAA + DPA | EU (Frankfurt / Dublin) | VERIFIED COMPLIANT | ||
| Supabase PostgreSQL | Postgres RLS & Vault | HIPAA BAA + DPA | EU (Frankfurt / Dublin) | VERIFIED COMPLIANT | ||
| Stripe Payments | PCI-DSS Gateway | PCI-DSS + DPA | Global Dual-Region | VERIFIED COMPLIANT | ||
| OpenAI Enterprise LLM | AI Inference Pipeline | Zero-Data DPA | US (N. Virginia) | VERIFIED COMPLIANT |
Quarterly User Access Review (UAR) Audit Log
SOC 2 CC6.3 & HIPAA § 164.312 privilege access recertification log.
Revoked inactive developer seats & verified 2FA enforcement.
Audited IAM access keys & rotated root account credentials.
Third-Party Risk Management (TPRM) Framework
Maintaining compliance across modern multi-cloud software stacks requires ongoing verification of vendor legal agreements, data processing addendums, and access credentials.
GDPR Article 28 DPA Tracking
Data controllers must only use processors providing sufficient guarantees. Enforces automated verification of Standard Contractual Clauses (SCCs) and data residency boundaries.
Data Erasure Guide →HIPAA § 164.502(e) BAA Execution
Covered entities and business associates must execute legally binding BAAs with any sub-contractor that creates, receives, maintains, or transmits electronic protected health information (ePHI).
BAA Checklist Guide →SOC 2 CC6.3 User Access Recertification
Enforces quarterly audits of privileged administrative access to production systems, automated offboarding checks, and multi-factor authentication (MFA) enforcement verification.
RBAC & MFA Guide →