Subprocessor register
Every provider has a purpose, boundary, owner, and exit.
This register covers providers that may process IT Modality or client information inside an approved service boundary. Engagement-specific additions remain visible in the applicable diligence record.
ForPeople conducting policy, privacy, security, or access review
FocusControls, ownership, evidence, and review paths
Table — scroll horizontally to review every column.
| Provider | Purpose | Data or access | Primary region | Last review |
|---|---|---|---|---|
| Northline Compute | Isolated application hosting and encrypted storage | Client-approved application and operational records | United States and Canada | May 2026 |
| HarborVault Continuity | Encrypted backup, retention, and restore | Encrypted service backups | United States | April 2026 |
| SignalWatch Operations | Availability, error, and security-event monitoring | Bounded telemetry; no content payload by default | United States and United Kingdom | June 2026 |
| LedgerMail Relay | Transactional service messages | Recipient address and message-routing metadata | United States | May 2026 |
| CivicTrust Signatures | Contract and approval signatures | Signatory identity, document, and audit metadata | United States and European Union | March 2026 |
Approval standard
Before a provider enters a client boundary, the operating owner records purpose, data flow, systems, locations, access, retention, deletion, security responsibilities, incident obligations, subcontracting, evidence, monitoring, and exit. The client and assigned legal, privacy, security, or procurement owners keep their approval rights.
Change control
A new provider, purpose, data class, region, downstream processor, access pattern, or retention period reopens review. Material changes are recorded, assessed, and communicated under the applicable engagement terms.