ssm.ro Docs
Compliance & Data ProtectionSuppliers & Third Parties

Vendor Management Policy

Selection, risk assessment, and monitoring of vendors and sub-processors

SSM.ro uses a limited number of trusted vendors for infrastructure and services. This policy governs their selection, risk assessment, and monitoring.

Selection and due diligence

The following are evaluated when selecting a vendor:

  • Security — certifications (ISO 27001, SOC 2), encryption practices, isolation
  • Compliance — the ability to comply with GDPR (data processing clauses)
  • Reliability — availability, SLA, reputation
  • Data location — the storage region and transfer implications

Vendor risk assessment

The risk of a third party / sub-processor being compromised is tracked in the Risk Register (risk #10), with controls:

  • TLS in transit for all vendors; mTLS or API token for the electronic signature provider
  • Limited credentials per vendor, with minimal privileges
  • Data minimization for data transmitted to each vendor

Contractual agreements

  • Data Processing Agreements (DPA / GDPR clauses) with vendors that process personal data
  • Confidentiality clauses for all collaborators and providers
  • Standard Contractual Clauses (SCC) for transfers outside the EEA

Continuous monitoring

  • Periodic review of critical vendors and their security status
  • Monitoring of service status (Heroku, AWS) for availability
  • Updated list of sub-processors: Sub-processors