Vendor + Subprocessor Management Policy

Owner: Security. Review cadence: annual or on material change. Approver: CEO.

This is the company-level policy for taking on, monitoring, and offboarding third-party vendors and subprocessors that touch MeterBox's Confidential or Restricted data. It is the intake + lifecycle counterpart to the BCP/DR policy § 8 (which covers vendor continuity) and the public subprocessor list (which is the current authoritative roster).

1 — Purpose + scope

A vendor or subprocessor is any third party MeterBox pays or contracts with that either (a) processes Confidential or Restricted data on MeterBox's behalf, or (b) is on the operational critical path for serving tenants (compute, identity, KMS, email, payment, observability).

In scope: every entry on the public subprocessor list, plus any future addition.

Out of scope: vendors that never see customer data and are not on the critical path (e.g. office supplies, marketing tools used only with aggregated/public data).

2 — Roles

3 — Intake gate

A new vendor MAY NOT be sent Confidential or Restricted data until all of the following have happened:

  1. Security review (§ 4) completed and recorded.
  2. DPA executed (Art. 28 GDPR; CCPA equivalent where applicable).
  3. Master service agreement or equivalent signed.
  4. Public subprocessor list updated, with ≥ 30 days notice to tenants per Art. 28(2) GDPR before the vendor goes live (notice is the listing being published; the listing commit date is the notification date).
  5. Engineering integration uses the least-privilege role + the smallest data scope that satisfies the use case.

A vendor that fails any of these is rejected or held until remediated.

4 — Security review checklist

The Security lead runs this on every intake and records the answers in a vendor file (private; not in this repo).

5 — Approval matrix

Vendor handles Approver
Public data only Security lead
Confidential data Security lead + CEO
Restricted data (cryptographic material, signed contracts) Security lead + CEO + Legal
Operationally critical (control plane, cloud, KMS, identity, payment) Security lead + CEO + Engineering lead

6 — Annual review

Every vendor is reviewed once per year. The Security lead:

  1. Re-collects the vendor's current attestation (SOC 2 letter / ISO cert).
  2. Confirms the DPA + data-residency commitments are still in force.
  3. Re-checks the sub-subprocessor list against the prior year — any additions reviewed individually.
  4. Confirms the integration scope hasn't crept beyond what was approved at intake.
  5. Records the review date on the vendor file + in the public subprocessor list (the listing's "last reviewed" field).

A vendor that fails review enters offboarding (§ 7) on a planned schedule unless remediation is possible within 30 days.

7 — Offboarding

When a vendor is dropped (planned replacement, end of life, failed review):

  1. Engineering lead disables the integration in production.
  2. Security lead requests the vendor's deletion certificate (MeterBox data destroyed within the contracted window).
  3. Public subprocessor list updated; tenants notified.
  4. Vendor file marked closed; retention per data retention policy.

8 — Sub-subprocessor change notification

Vendor adds a sub-subprocessor: vendor notifies MeterBox → Security lead reviews against § 4 → if approved, the public subprocessor list is updated within 30 days. Material changes that fail review trigger vendor offboarding (§ 7).

9 — Review + version control

This policy is reviewed annually or on material change (new vendor category, new regulator requirement, new high-impact subprocessor).

Last reviewed: 2026-06-04

Related docs