Managing Vendors and Sub-Processors
Keep an inventory of the vendors that process data for you, link them to the data systems they support, and publish your sub-processor list to your Trust Center.
Overview
Your vendors are the third parties that store or process data on your behalf, and buyers increasingly ask you to name them. Concord keeps a vendor inventory alongside your Data Mapping, so the vendors you track are connected to the systems they actually support, and the sub-processor list you publish stays consistent with your data map.
Adding vendors
From Data Mapping → Vendors, add each vendor you rely on. Recording a vendor in one place means the same information feeds your data map, your sub-processor list, and the answers you give during security reviews.
Linking vendors to data systems
Link a vendor to the data systems it supports. This keeps your data map honest about who is involved in each system and makes it clear, per system, which third parties have access to the data it holds.
Publishing sub-processors to your Trust Center
You can publish your sub-processor list to your public Trust Center, so prospects and customers can see who processes their data without emailing your team. Publishing from your maintained vendor list keeps the public list current instead of drifting from a separate document. See Trust Center overview for how the public page is organized.
Who can manage vendors
Owners and Admins can add and edit vendors and publish sub-processors. A Limited user can view them. See User Roles & Permissions.