Skip to content

Third-Party / Vendor Risk Management Policy

Field Value
Owner Puneet Gupta (Co-Founder)
Classification Internal (shareable under NDA)
Version 1.0
Effective date 2026-06-11
Next review 2027-06-11

1. Purpose

Define how Revzio assesses and manages security and privacy risk from third parties (subprocessors) and their fourth parties.

2. Scope

All vendors and subprocessors that store, process, or transmit Revzio or customer data, or that are critical to delivering the service (e.g. database, LLM, authentication, payment, and ERP providers).

3. Selection & onboarding

Before onboarding a subprocessor that handles data, Revzio:

  1. Reviews the vendor's security posture, favouring providers holding recognized attestations (SOC 2 Type 2 / ISO 27001).
  2. Reviews / executes a Data Processing Agreement (DPA) where personal data is involved.
  3. Records the vendor, the data it handles, and its attestation/DPA status in the Subprocessor Register.

4. Ongoing management

  • The subprocessor register is reviewed periodically and on change.
  • Material changes to a subprocessor's security posture or sub-processing are assessed.
  • Fourth-party risk (a subprocessor's own providers, e.g. the cloud platform underlying a managed service) is considered via the subprocessor's attestations.

5. Customer notification

Customers are informed of subprocessors per the customer agreement; material changes are communicated as required.

Revision history

Version Date Author Change Approved by
1.0 2026-06-11 Puneet Gupta Initial draft Puneet Gupta (Co-Founder)