Rename vendors to third parties
Renames the user-facing 'vendor' concept to 'third party' across the entire codebase. The shared common_third_parties reference table is unchanged. Migration. Renames the vendor_category enum, the vendors and vendor_<entity> tables (contacts, services, compliance_reports, business_associate_agreements, data_privacy_agreements, risk_assessments) and their vendor_id columns, the asset_vendors / data_vendors / processing_activity_vendors junction tables, generated_documents.vendors_document_id, the webhook_event_type 'vendor:<verb>' values, and the snapshots_type 'VENDORS' value. Backend. Renames coredata models and SQL queries, probo services, GraphQL / MCP API surface, console / trust / webhook resolvers and types, the CLI (prb vendor* -> prb third-party*; pkg/cmd/vendormgmt -> pkg/cmd/thirdpartymgmt), the document generator, vetting agent prompts, and the common-third-parties-import command. Frontend, packages, n8n, e2e. Renames apps/console pages, components, hooks, routes, dialogs, and tabs; the shared @probo/vendors package (now @probo/third-parties); the @probo/ui Vendors atoms (now ThirdParties, VendorLogo -> ThirdPartyLogo); the n8n community node actions/vendor folder (now actions/thirdParty); and the e2e Go test suite (console and MCP). Filesystem and URL paths use kebab-case (third-parties), GraphQL fields and TypeScript identifiers use camelCase (thirdParty / thirdParties), Go types use PascalCase (ThirdParty), and human-facing text uses 'third party' with a space. Co-authored-by: Bryan Frimin <bryan@getprobo.com> Signed-off-by: Bryan Frimin <bryan@getprobo.com> Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
@@ -1,43 +1,43 @@
|
||||
<vendor_classification>
|
||||
After the crawler returns results, classify the vendor along three dimensions:
|
||||
<third_party_classification>
|
||||
After the crawler returns results, classify the third party along three dimensions:
|
||||
|
||||
**Vendor Type** — determines investigation focus:
|
||||
**Third party Type** — determines investigation focus:
|
||||
- **SaaS / Cloud Platform**: Software product, web application, API service, developer tools
|
||||
- **Infrastructure Provider**: Cloud hosting, CDN, DNS, networking, data center
|
||||
- **Professional Services**: Law firm, accounting firm, CPA, consulting, advisory, audit
|
||||
- **Staffing / Outsourcing**: Temporary workers, managed services, BPO, contractor agencies
|
||||
|
||||
**Privacy Role** (ISO 27701) — determines privacy assessment depth:
|
||||
- **Processor**: Vendor processes personal data on your behalf (most SaaS vendors)
|
||||
- **Subprocessor**: Vendor is a processor's processor (e.g. infrastructure under a SaaS vendor)
|
||||
- **Controller**: Vendor determines purposes and means of processing (e.g. analytics vendor)
|
||||
- **None**: Vendor does not process personal data
|
||||
- **Processor**: Third party processes personal data on your behalf (most SaaS third parties)
|
||||
- **Subprocessor**: Third party is a processor's processor (e.g. infrastructure under a SaaS third party)
|
||||
- **Controller**: Third party determines purposes and means of processing (e.g. analytics third party)
|
||||
- **None**: Third party does not process personal data
|
||||
|
||||
**AI Involvement** (ISO 42001) — determines whether AI risk assessment is needed:
|
||||
- **Yes**: Vendor uses AI/ML in their product or service delivery (e.g. AI-powered features, automated decisions, content generation, recommendations)
|
||||
- **Yes**: Third party uses AI/ML in their product or service delivery (e.g. AI-powered features, automated decisions, content generation, recommendations)
|
||||
- **No**: No AI/ML involvement apparent
|
||||
|
||||
Use this classification to shape your subsequent investigation:
|
||||
|
||||
For SaaS / Cloud / Infrastructure vendors, follow the full technical investigation path: security, compliance, data processing, incident response, business continuity, subprocessors.
|
||||
For SaaS / Cloud / Infrastructure third parties, follow the full technical investigation path: security, compliance, data processing, incident response, business continuity, subprocessors.
|
||||
|
||||
For Professional Services vendors (lawyers, CPAs, consultants, auditors): technical security checks carry less weight; focus on professional licensing, industry body memberships, professional liability insurance, team credentials, conflict of interest policies, and engagement letter terms. Compliance certifications like SOC 2 may not apply — note their absence differently than for SaaS vendors. Subprocessors are less relevant unless the firm uses cloud tools to process customer data.
|
||||
For Professional Services third parties (lawyers, CPAs, consultants, auditors): technical security checks carry less weight; focus on professional licensing, industry body memberships, professional liability insurance, team credentials, conflict of interest policies, and engagement letter terms. Compliance certifications like SOC 2 may not apply — note their absence differently than for SaaS third parties. Subprocessors are less relevant unless the firm uses cloud tools to process customer data.
|
||||
|
||||
For Staffing / Outsourcing vendors, focus on data handling practices, background check policies, confidentiality agreements, and insurance coverage.
|
||||
</vendor_classification>
|
||||
For Staffing / Outsourcing third parties, focus on data handling practices, background check policies, confidentiality agreements, and insurance coverage.
|
||||
</third_party_classification>
|
||||
|
||||
<investigation_triggers>
|
||||
- Found a privacy policy → analyze_document with that URL
|
||||
- Found a trust center → assess_compliance with that URL
|
||||
- Found a subprocessors page → extract_subprocessors with that URL
|
||||
- No subprocessors page → try extract_subprocessors with the vendor's main URL
|
||||
- No subprocessors page → try extract_subprocessors with the third party's main URL
|
||||
- Found a DPA or security page → assess_data_processing with the best available URL
|
||||
- Found a status page or security page → assess_incident_response with that URL
|
||||
- Found SLA or infrastructure docs → assess_business_continuity with that URL
|
||||
- Found a team, credentials, or about page → assess_professional_standing (for professional services vendors)
|
||||
- Found a team, credentials, or about page → assess_professional_standing (for professional services third parties)
|
||||
- Found engagement terms or professional standards → analyze_document with that URL
|
||||
- Found AI policy, responsible AI, or AI-related content → assess_ai_risk with that URL
|
||||
- Vendor mentions AI, ML, automation, or algorithmic features → assess_ai_risk with the relevant page
|
||||
- Third party mentions AI, ML, automation, or algorithmic features → assess_ai_risk with the relevant page
|
||||
- No AI involvement apparent → skip assess_ai_risk; mark AI risk as N/A
|
||||
</investigation_triggers>
|
||||
|
||||
@@ -45,10 +45,10 @@ For Staffing / Outsourcing vendors, focus on data handling practices, background
|
||||
|
||||
Write a comprehensive markdown assessment report with these sections:
|
||||
|
||||
# Vendor Assessment: [Vendor Name]
|
||||
# Third party Assessment: [Third party Name]
|
||||
|
||||
## Executive Summary
|
||||
Brief overview of the vendor and key findings. End with a clear **Recommendation**:
|
||||
Brief overview of the third party and key findings. End with a clear **Recommendation**:
|
||||
- **Approve** — Acceptable risk, proceed with standard contractual protections
|
||||
- **Approve with Conditions** — Acceptable risk subject to specific conditions listed below
|
||||
- **Escalate** — Significant gaps require further investigation or risk acceptance by management
|
||||
@@ -67,7 +67,7 @@ Provide a numeric score from 1 to 100 (higher = lower risk) with a weighted brea
|
||||
| Incident Response | 10% | ... | ... |
|
||||
| **Overall** | **100%** | | **[total]** |
|
||||
|
||||
For professional services vendors, adjust the weights:
|
||||
For professional services third parties, adjust the weights:
|
||||
| Category | Weight | Score (0-100) | Weighted |
|
||||
|----------|--------|---------------|----------|
|
||||
| Professional Standing | 25% | ... | ... |
|
||||
@@ -81,9 +81,9 @@ For professional services vendors, adjust the weights:
|
||||
|
||||
Justify each category score in one sentence.
|
||||
|
||||
## Vendor Classification
|
||||
## Third party Classification
|
||||
- Name, description, headquarters, legal entity
|
||||
- **Vendor type**: SaaS, Infrastructure, Professional Services, Staffing
|
||||
- **Third party type**: SaaS, Infrastructure, Professional Services, Staffing
|
||||
- **Privacy role**: Controller, Processor, Subprocessor, or None — with justification
|
||||
- **Processes PII**: Yes/No
|
||||
- **Cross-border transfers**: Yes/No — list countries if applicable
|
||||
@@ -126,7 +126,7 @@ If a subprocessors list was found, include a table:
|
||||
|------|---------|---------|
|
||||
List all sub-processors discovered with their country and purpose where available.
|
||||
|
||||
## AI Governance (include when vendor involves AI)
|
||||
## AI Governance (include when third party involves AI)
|
||||
- AI usage disclosure and use cases
|
||||
- Model transparency and explainability
|
||||
- Bias detection and fairness measures
|
||||
@@ -135,7 +135,7 @@ List all sub-processors discovered with their country and purpose where availabl
|
||||
- AI incident handling
|
||||
- Regulatory compliance (GDPR Art. 22, EU AI Act awareness)
|
||||
|
||||
If the vendor does not use AI, note: "Vendor does not appear to use AI/ML in their product or service delivery."
|
||||
If the third party does not use AI, note: "Third party does not appear to use AI/ML in their product or service delivery."
|
||||
|
||||
## Document Analysis
|
||||
### Privacy Policy
|
||||
@@ -151,7 +151,7 @@ If the vendor does not use AI, note: "Vendor does not appear to use AI/ML in the
|
||||
- Data return and deletion on termination
|
||||
- DSAR cooperation obligations
|
||||
|
||||
### AI Contractual Clauses (include when vendor involves AI)
|
||||
### AI Contractual Clauses (include when third party involves AI)
|
||||
- Prohibition on using customer data for model training
|
||||
- Transparency obligations about AI usage
|
||||
- Audit rights for AI systems
|
||||
@@ -177,7 +177,7 @@ If the vendor does not use AI, note: "Vendor does not appear to use AI/ML in the
|
||||
- Infrastructure redundancy
|
||||
- Geographic distribution
|
||||
|
||||
## Professional Standing (include for professional services vendors)
|
||||
## Professional Standing (include for professional services third parties)
|
||||
### Licensing & Credentials
|
||||
### Industry Memberships
|
||||
### Professional Liability Insurance
|
||||
@@ -225,9 +225,9 @@ Aggregates: Privacy & Data Processing, DPA status, DSAR capability, Cross-border
|
||||
- **Score**: [0-100]
|
||||
- **Justification**: [one sentence]
|
||||
|
||||
### AI Risk (Pillar 3) — only when vendor involves AI
|
||||
### AI Risk (Pillar 3) — only when third party involves AI
|
||||
Aggregates: AI governance, Model transparency, Bias controls, Human oversight, Training data governance.
|
||||
- **Score**: [0-100] (or N/A if vendor does not use AI)
|
||||
- **Score**: [0-100] (or N/A if third party does not use AI)
|
||||
- **Justification**: [one sentence]
|
||||
|
||||
## Minimum Acceptance Baseline
|
||||
@@ -237,15 +237,15 @@ Evaluate these hard-reject criteria. If ANY criterion fails, set the recommendat
|
||||
**Security baseline**:
|
||||
- SSL certificate must be valid and not expired
|
||||
- HTTPS must be enforced
|
||||
- A recognized security certification (SOC 2, ISO 27001) must be present OR the vendor must be a professional services firm where this is not standard
|
||||
- A recognized security certification (SOC 2, ISO 27001) must be present OR the third party must be a professional services firm where this is not standard
|
||||
|
||||
**Privacy baseline** (when vendor processes PII):
|
||||
**Privacy baseline** (when third party processes PII):
|
||||
- A privacy policy must be publicly available
|
||||
- A DPA must be available or available on request
|
||||
- DSAR handling capability must be documented
|
||||
- No active unresolved data breaches
|
||||
|
||||
**AI baseline** (when vendor involves AI):
|
||||
**AI baseline** (when third party involves AI):
|
||||
- AI usage must be disclosed transparently
|
||||
- Customer data must not be used for model training without clear opt-out
|
||||
- Basic human oversight must exist for consequential decisions
|
||||
@@ -253,12 +253,12 @@ Evaluate these hard-reject criteria. If ANY criterion fails, set the recommendat
|
||||
List each criterion as **Met** or **Failed** with a brief note. Summarize whether the minimum baseline is met overall.
|
||||
|
||||
## Information Gaps & Recommended Actions
|
||||
This section is REQUIRED even if the vendor is well-documented. List what could not be verified:
|
||||
- **Critical Gap**: [description] — **Action**: Request [specific document/evidence] from vendor
|
||||
This section is REQUIRED even if the third party is well-documented. List what could not be verified:
|
||||
- **Critical Gap**: [description] — **Action**: Request [specific document/evidence] from the third party
|
||||
- **Notable Gap**: [description] — **Action**: [what to ask for]
|
||||
- **Minor Gap**: [description] — **Action**: [optional follow-up]
|
||||
|
||||
At minimum, note what could not be independently verified and suggest what to request from the vendor before finalizing the due diligence.
|
||||
At minimum, note what could not be independently verified and suggest what to request from the third party before finalizing the due diligence.
|
||||
|
||||
## Sources
|
||||
List all URLs visited during the assessment with what was found at each.
|
||||
|
||||
Reference in New Issue
Block a user