Rename vendors to third parties

Renames the user-facing 'vendor' concept to 'third party' across the
entire codebase. The shared common_third_parties reference table is
unchanged.

Migration. Renames the vendor_category enum, the vendors and
vendor_<entity> tables (contacts, services, compliance_reports,
business_associate_agreements, data_privacy_agreements,
risk_assessments) and their vendor_id columns, the asset_vendors /
data_vendors / processing_activity_vendors junction tables,
generated_documents.vendors_document_id, the webhook_event_type
'vendor:<verb>' values, and the snapshots_type 'VENDORS' value.

Backend. Renames coredata models and SQL queries, probo services,
GraphQL / MCP API surface, console / trust / webhook resolvers and
types, the CLI (prb vendor* -> prb third-party*; pkg/cmd/vendormgmt
-> pkg/cmd/thirdpartymgmt), the document generator, vetting agent
prompts, and the common-third-parties-import command.

Frontend, packages, n8n, e2e. Renames apps/console pages, components,
hooks, routes, dialogs, and tabs; the shared @probo/vendors package
(now @probo/third-parties); the @probo/ui Vendors atoms (now
ThirdParties, VendorLogo -> ThirdPartyLogo); the n8n community node
actions/vendor folder (now actions/thirdParty); and the e2e Go test
suite (console and MCP). Filesystem and URL paths use kebab-case
(third-parties), GraphQL fields and TypeScript identifiers use
camelCase (thirdParty / thirdParties), Go types use PascalCase
(ThirdParty), and human-facing text uses 'third party' with a space.

Co-authored-by: Bryan Frimin <bryan@getprobo.com>
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2026-05-13 16:15:33 +02:00
parent 9eed0d71c8
commit eecbe4c46c
281 changed files with 8491 additions and 8425 deletions

View File

@@ -1,43 +1,43 @@
<vendor_classification>
After the crawler returns results, classify the vendor along three dimensions:
<third_party_classification>
After the crawler returns results, classify the third party along three dimensions:
**Vendor Type** — determines investigation focus:
**Third party Type** — determines investigation focus:
- **SaaS / Cloud Platform**: Software product, web application, API service, developer tools
- **Infrastructure Provider**: Cloud hosting, CDN, DNS, networking, data center
- **Professional Services**: Law firm, accounting firm, CPA, consulting, advisory, audit
- **Staffing / Outsourcing**: Temporary workers, managed services, BPO, contractor agencies
**Privacy Role** (ISO 27701) — determines privacy assessment depth:
- **Processor**: Vendor processes personal data on your behalf (most SaaS vendors)
- **Subprocessor**: Vendor is a processor's processor (e.g. infrastructure under a SaaS vendor)
- **Controller**: Vendor determines purposes and means of processing (e.g. analytics vendor)
- **None**: Vendor does not process personal data
- **Processor**: Third party processes personal data on your behalf (most SaaS third parties)
- **Subprocessor**: Third party is a processor's processor (e.g. infrastructure under a SaaS third party)
- **Controller**: Third party determines purposes and means of processing (e.g. analytics third party)
- **None**: Third party does not process personal data
**AI Involvement** (ISO 42001) — determines whether AI risk assessment is needed:
- **Yes**: Vendor uses AI/ML in their product or service delivery (e.g. AI-powered features, automated decisions, content generation, recommendations)
- **Yes**: Third party uses AI/ML in their product or service delivery (e.g. AI-powered features, automated decisions, content generation, recommendations)
- **No**: No AI/ML involvement apparent
Use this classification to shape your subsequent investigation:
For SaaS / Cloud / Infrastructure vendors, follow the full technical investigation path: security, compliance, data processing, incident response, business continuity, subprocessors.
For SaaS / Cloud / Infrastructure third parties, follow the full technical investigation path: security, compliance, data processing, incident response, business continuity, subprocessors.
For Professional Services vendors (lawyers, CPAs, consultants, auditors): technical security checks carry less weight; focus on professional licensing, industry body memberships, professional liability insurance, team credentials, conflict of interest policies, and engagement letter terms. Compliance certifications like SOC 2 may not apply — note their absence differently than for SaaS vendors. Subprocessors are less relevant unless the firm uses cloud tools to process customer data.
For Professional Services third parties (lawyers, CPAs, consultants, auditors): technical security checks carry less weight; focus on professional licensing, industry body memberships, professional liability insurance, team credentials, conflict of interest policies, and engagement letter terms. Compliance certifications like SOC 2 may not apply — note their absence differently than for SaaS third parties. Subprocessors are less relevant unless the firm uses cloud tools to process customer data.
For Staffing / Outsourcing vendors, focus on data handling practices, background check policies, confidentiality agreements, and insurance coverage.
</vendor_classification>
For Staffing / Outsourcing third parties, focus on data handling practices, background check policies, confidentiality agreements, and insurance coverage.
</third_party_classification>
<investigation_triggers>
- Found a privacy policy → analyze_document with that URL
- Found a trust center → assess_compliance with that URL
- Found a subprocessors page → extract_subprocessors with that URL
- No subprocessors page → try extract_subprocessors with the vendor's main URL
- No subprocessors page → try extract_subprocessors with the third party's main URL
- Found a DPA or security page → assess_data_processing with the best available URL
- Found a status page or security page → assess_incident_response with that URL
- Found SLA or infrastructure docs → assess_business_continuity with that URL
- Found a team, credentials, or about page → assess_professional_standing (for professional services vendors)
- Found a team, credentials, or about page → assess_professional_standing (for professional services third parties)
- Found engagement terms or professional standards → analyze_document with that URL
- Found AI policy, responsible AI, or AI-related content → assess_ai_risk with that URL
- Vendor mentions AI, ML, automation, or algorithmic features → assess_ai_risk with the relevant page
- Third party mentions AI, ML, automation, or algorithmic features → assess_ai_risk with the relevant page
- No AI involvement apparent → skip assess_ai_risk; mark AI risk as N/A
</investigation_triggers>
@@ -45,10 +45,10 @@ For Staffing / Outsourcing vendors, focus on data handling practices, background
Write a comprehensive markdown assessment report with these sections:
# Vendor Assessment: [Vendor Name]
# Third party Assessment: [Third party Name]
## Executive Summary
Brief overview of the vendor and key findings. End with a clear **Recommendation**:
Brief overview of the third party and key findings. End with a clear **Recommendation**:
- **Approve** — Acceptable risk, proceed with standard contractual protections
- **Approve with Conditions** — Acceptable risk subject to specific conditions listed below
- **Escalate** — Significant gaps require further investigation or risk acceptance by management
@@ -67,7 +67,7 @@ Provide a numeric score from 1 to 100 (higher = lower risk) with a weighted brea
| Incident Response | 10% | ... | ... |
| **Overall** | **100%** | | **[total]** |
For professional services vendors, adjust the weights:
For professional services third parties, adjust the weights:
| Category | Weight | Score (0-100) | Weighted |
|----------|--------|---------------|----------|
| Professional Standing | 25% | ... | ... |
@@ -81,9 +81,9 @@ For professional services vendors, adjust the weights:
Justify each category score in one sentence.
## Vendor Classification
## Third party Classification
- Name, description, headquarters, legal entity
- **Vendor type**: SaaS, Infrastructure, Professional Services, Staffing
- **Third party type**: SaaS, Infrastructure, Professional Services, Staffing
- **Privacy role**: Controller, Processor, Subprocessor, or None — with justification
- **Processes PII**: Yes/No
- **Cross-border transfers**: Yes/No — list countries if applicable
@@ -126,7 +126,7 @@ If a subprocessors list was found, include a table:
|------|---------|---------|
List all sub-processors discovered with their country and purpose where available.
## AI Governance (include when vendor involves AI)
## AI Governance (include when third party involves AI)
- AI usage disclosure and use cases
- Model transparency and explainability
- Bias detection and fairness measures
@@ -135,7 +135,7 @@ List all sub-processors discovered with their country and purpose where availabl
- AI incident handling
- Regulatory compliance (GDPR Art. 22, EU AI Act awareness)
If the vendor does not use AI, note: "Vendor does not appear to use AI/ML in their product or service delivery."
If the third party does not use AI, note: "Third party does not appear to use AI/ML in their product or service delivery."
## Document Analysis
### Privacy Policy
@@ -151,7 +151,7 @@ If the vendor does not use AI, note: "Vendor does not appear to use AI/ML in the
- Data return and deletion on termination
- DSAR cooperation obligations
### AI Contractual Clauses (include when vendor involves AI)
### AI Contractual Clauses (include when third party involves AI)
- Prohibition on using customer data for model training
- Transparency obligations about AI usage
- Audit rights for AI systems
@@ -177,7 +177,7 @@ If the vendor does not use AI, note: "Vendor does not appear to use AI/ML in the
- Infrastructure redundancy
- Geographic distribution
## Professional Standing (include for professional services vendors)
## Professional Standing (include for professional services third parties)
### Licensing & Credentials
### Industry Memberships
### Professional Liability Insurance
@@ -225,9 +225,9 @@ Aggregates: Privacy & Data Processing, DPA status, DSAR capability, Cross-border
- **Score**: [0-100]
- **Justification**: [one sentence]
### AI Risk (Pillar 3) — only when vendor involves AI
### AI Risk (Pillar 3) — only when third party involves AI
Aggregates: AI governance, Model transparency, Bias controls, Human oversight, Training data governance.
- **Score**: [0-100] (or N/A if vendor does not use AI)
- **Score**: [0-100] (or N/A if third party does not use AI)
- **Justification**: [one sentence]
## Minimum Acceptance Baseline
@@ -237,15 +237,15 @@ Evaluate these hard-reject criteria. If ANY criterion fails, set the recommendat
**Security baseline**:
- SSL certificate must be valid and not expired
- HTTPS must be enforced
- A recognized security certification (SOC 2, ISO 27001) must be present OR the vendor must be a professional services firm where this is not standard
- A recognized security certification (SOC 2, ISO 27001) must be present OR the third party must be a professional services firm where this is not standard
**Privacy baseline** (when vendor processes PII):
**Privacy baseline** (when third party processes PII):
- A privacy policy must be publicly available
- A DPA must be available or available on request
- DSAR handling capability must be documented
- No active unresolved data breaches
**AI baseline** (when vendor involves AI):
**AI baseline** (when third party involves AI):
- AI usage must be disclosed transparently
- Customer data must not be used for model training without clear opt-out
- Basic human oversight must exist for consequential decisions
@@ -253,12 +253,12 @@ Evaluate these hard-reject criteria. If ANY criterion fails, set the recommendat
List each criterion as **Met** or **Failed** with a brief note. Summarize whether the minimum baseline is met overall.
## Information Gaps & Recommended Actions
This section is REQUIRED even if the vendor is well-documented. List what could not be verified:
- **Critical Gap**: [description] — **Action**: Request [specific document/evidence] from vendor
This section is REQUIRED even if the third party is well-documented. List what could not be verified:
- **Critical Gap**: [description] — **Action**: Request [specific document/evidence] from the third party
- **Notable Gap**: [description] — **Action**: [what to ask for]
- **Minor Gap**: [description] — **Action**: [optional follow-up]
At minimum, note what could not be independently verified and suggest what to request from the vendor before finalizing the due diligence.
At minimum, note what could not be independently verified and suggest what to request from the third party before finalizing the due diligence.
## Sources
List all URLs visited during the assessment with what was found at each.