Skip to main content

third partyVersion 1SOC2ISO27001NIST800-171GDPR

Vendor & Subprocessor Management Policy

Onboarding, monitoring, and termination of third parties handling Rex Black data.

Download PDFSHA-256 6ed58675c8641513…

Vendor & Subprocessor Management Policy

1. Purpose

Ensures every third-party service that processes Rex Black or client data is evaluated for security, privacy, and legal risk before onboarding, and monitored thereafter.

2. Definitions

  • Vendor: any third party Rex Black pays for a service.
  • Subprocessor: a vendor that processes client personal data on Rex Black's behalf.
  • Critical vendor: a vendor whose failure would materially disrupt Rex Black operations (e.g., AWS, Stripe, Google Workspace).

3. Onboarding

For every new vendor processing Confidential or Restricted data:

  1. Business justification documented by the requesting owner.
  2. Security questionnaire or review of vendor's SOC 2 Type II / ISO 27001 report. SOC 2 Type I alone is not sufficient for critical vendors after 12 months in market.
  3. Data Processing Agreement (DPA) in place for subprocessors that process personal data. SCCs for transfers outside the EU/UK.
  4. Scope of data shared: the Security Officer confirms the vendor gets only the minimum data needed.
  5. Integration review: auth method, scopes, secret storage, logging, rotation.
  6. Record added to registers/subprocessors.md with classification, data types, and approval.

4. Monitoring

  1. Annual review of each critical vendor's attestations, status page reliability, and incident history.
  2. Continuous: vendor security bulletins monitored; incidents trigger risk re-assessment.
  3. Attestation refresh: vendor SOC 2 / ISO reports requested on renewal. Gaps in attestation coverage are flagged in the Risk Register.

5. Termination

  1. Offboarding triggers: contract ends, security degradation, unresolved high-severity incident, change of control.
  2. Access revoked, API keys rotated, data returned or certified destroyed per the DPA.
  3. Entry archived in the subprocessor register with offboarding date.

6. Subprocessor disclosure

  1. The active subprocessor list is published at https://rexblack.com/trust/subprocessors and refreshed when the underlying register changes.
  2. Clients are notified by email at least 30 days before a new subprocessor for their data is engaged, unless the contract specifies a different notice period.

7. High-risk categories

Additional diligence applies for vendors handling:

  • Authentication secrets or tokens.
  • Payment data (PCI DSS-relevant).
  • CUI (vendor must have a compliant Cloud Service Offering).
  • Protected health information (BAA required; HIPAA applies).

8. Roles & responsibilities

Role Responsibility
Security Officer Approves vendors; maintains register.
Privacy Officer Approves DPAs; runs transfer-impact assessments.
Requesting owner Provides justification; owns ongoing relationship.

9. Enforcement & exceptions

Vendors introduced without onboarding are blocked. Exceptions require Security Officer + Privacy Officer written approval with a remediation plan.

10. References

  • registers/subprocessors.md
  • 027-third-party-risk-assessment-policy.md
  • 028-data-subject-rights-policy.md

11. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center