Vendor & Sub-processor Management Policy
1. Purpose
This policy describes how we select, evaluate, and monitor the third-party vendors and sub-processors AetherCloud depends on. Our current sub-processor list is published on our Trust page.
2. Selection criteria
Before adopting a new vendor for any function that touches customer data or production infrastructure, we evaluate: whether the vendor publishes its own security/compliance posture (SOC 2 report, security page, or equivalent), what data it would receive and why that's the minimum necessary, and whether a lower-risk alternative would serve the same purpose.
3. Criticality tiering
We maintain an internal risk register classifying each dependency by criticality (what breaks if it's unavailable) and by the alternatives available if we needed to switch. This isn't published in full (it doubles as an internal risk-planning document), but its contents inform the sub-processor list on our Trust page and are available to prospective customers on request as part of a completed security questionnaire.
4. Ongoing monitoring
We monitor our sub-processors' own status/incident pages and update our published Trust page sub-processor list when a vendor is added, removed, or changes scope — the Trust page is our authoritative, most current list. We work to keep the corresponding section of our Privacy Policy in sync as part of routine review, rather than on a fixed annual cycle.
5. Data processing agreements
Where a sub-processor offers a data processing agreement (DPA) or equivalent contractual data-protection terms, we execute it. This is an ongoing process as our vendor relationships mature — reach out to [email protected] if you need confirmation of a specific sub-processor's contractual terms for your own vendor-risk review.