Skip to main content

Subprocessor register

Every provider has a purpose, boundary, owner, and exit.

This register covers providers that may process IT Modality or client information inside an approved service boundary. Engagement-specific additions remain visible in the applicable diligence record.

ForPeople conducting policy, privacy, security, or access review

FocusControls, ownership, evidence, and review paths

Table — scroll horizontally to review every column.

ProviderPurposeData or accessPrimary regionLast review
Northline ComputeIsolated application hosting and encrypted storageClient-approved application and operational recordsUnited States and CanadaMay 2026
HarborVault ContinuityEncrypted backup, retention, and restoreEncrypted service backupsUnited StatesApril 2026
SignalWatch OperationsAvailability, error, and security-event monitoringBounded telemetry; no content payload by defaultUnited States and United KingdomJune 2026
LedgerMail RelayTransactional service messagesRecipient address and message-routing metadataUnited StatesMay 2026
CivicTrust SignaturesContract and approval signaturesSignatory identity, document, and audit metadataUnited States and European UnionMarch 2026

Approval standard

Before a provider enters a client boundary, the operating owner records purpose, data flow, systems, locations, access, retention, deletion, security responsibilities, incident obligations, subcontracting, evidence, monitoring, and exit. The client and assigned legal, privacy, security, or procurement owners keep their approval rights.

Change control

A new provider, purpose, data class, region, downstream processor, access pattern, or retention period reopens review. Material changes are recorded, assessed, and communicated under the applicable engagement terms.

Review security and data handling

Start a provider conversation.