third partyVersion 1SOC2ISO27001NIST800-171GDPR
Vendor & Subprocessor Management Policy
Onboarding, monitoring, and termination of third parties handling Rex Black data.
Vendor & Subprocessor Management Policy
1. Purpose
Ensures every third-party service that processes Rex Black or client data is evaluated for security, privacy, and legal risk before onboarding, and monitored thereafter.
2. Definitions
- Vendor: any third party Rex Black pays for a service.
- Subprocessor: a vendor that processes client personal data on Rex Black's behalf.
- Critical vendor: a vendor whose failure would materially disrupt Rex Black operations (e.g., AWS, Stripe, Google Workspace).
3. Onboarding
For every new vendor processing Confidential or Restricted data:
- Business justification documented by the requesting owner.
- Security questionnaire or review of vendor's SOC 2 Type II / ISO 27001 report. SOC 2 Type I alone is not sufficient for critical vendors after 12 months in market.
- Data Processing Agreement (DPA) in place for subprocessors that process personal data. SCCs for transfers outside the EU/UK.
- Scope of data shared: the Security Officer confirms the vendor gets only the minimum data needed.
- Integration review: auth method, scopes, secret storage, logging, rotation.
- Record added to
registers/subprocessors.mdwith classification, data types, and approval.
4. Monitoring
- Annual review of each critical vendor's attestations, status page reliability, and incident history.
- Continuous: vendor security bulletins monitored; incidents trigger risk re-assessment.
- Attestation refresh: vendor SOC 2 / ISO reports requested on renewal. Gaps in attestation coverage are flagged in the Risk Register.
5. Termination
- Offboarding triggers: contract ends, security degradation, unresolved high-severity incident, change of control.
- Access revoked, API keys rotated, data returned or certified destroyed per the DPA.
- Entry archived in the subprocessor register with offboarding date.
6. Subprocessor disclosure
- The active subprocessor list is published at
https://rexblack.com/trust/subprocessorsand refreshed when the underlying register changes. - Clients are notified by email at least 30 days before a new subprocessor for their data is engaged, unless the contract specifies a different notice period.
7. High-risk categories
Additional diligence applies for vendors handling:
- Authentication secrets or tokens.
- Payment data (PCI DSS-relevant).
- CUI (vendor must have a compliant Cloud Service Offering).
- Protected health information (BAA required; HIPAA applies).
8. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Approves vendors; maintains register. |
| Privacy Officer | Approves DPAs; runs transfer-impact assessments. |
| Requesting owner | Provides justification; owns ongoing relationship. |
9. Enforcement & exceptions
Vendors introduced without onboarding are blocked. Exceptions require Security Officer + Privacy Officer written approval with a remediation plan.
10. References
registers/subprocessors.md027-third-party-risk-assessment-policy.md028-data-subject-rights-policy.md
11. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.