Supply chain
How third parties are selected, bounded and monitored — and how you assess the chain rather than only the vendor in front of you.
Last updated 23 July 2026 · Trust Center
1. The register
The subprocessor register is two-tier. Microsoft Azure (hosting, all environments) and Twilio (SMS and telephony) are constants. Everything else is deployment-specific and issued as a completed Exhibit C, because a single published list would be wrong for almost every deployment — either overstating who touches your data or omitting a party a specific integration introduces.
2. Selection
A third party is assessed on the security and privacy posture appropriate to what it will process, its own subprocessor chain, its residency options, its breach-notification commitments, and whether we can leave it. The last one is assessed before onboarding rather than after.
3. Contractual bounding
Each subprocessor is bound by data-protection obligations no less protective than those in the DPA, and we remain responsible for its performance. A subprocessor receives only the data its function requires — scope is part of the engagement, not a matter of trust.
4. Notice and objection
We give notice of an intended new or replacement subprocessor that will process your personal data, with a reasonable period to object on reasonable data-protection grounds. If a well-founded objection cannot be accommodated you may terminate the affected service. Notices go to a named address you give us — send it to legal@a8core.com.
5. Monitoring
Subprocessors are reviewed periodically and on trigger — a breach, a material change of control, a change in residency, or a lapse in the assurance they rely on. A review that only happens annually will always be out of date at the moment it matters.
6. Your own assessment
You are assessing a chain, not a vendor. Request the three DPA exhibits together — A (nature of processing), B (technical and organisational measures) and C (subprocessors with role and region). Those three are what a vendor-risk file needs, and requesting them separately is how a review takes three weeks instead of three days.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice. Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.