Discovery queue open Typical turnaround: one working day The register Method Talk to a reviewer
subprocessor.org
Six sources. One reviewed list. Re-checked daily.See how the work flows →
Same engine, different job to be done.Compare the tiers →
We publish observations and dated records, never legal conclusions.Read the method →
Free to read. No account.Open the register →
the platform

What it does, end to end.

Discovery, publication, upkeep and proof. Each part exists because the one before it is useless without it — a list nobody maintains, or a change nobody can evidence, solves nothing.

Free discoveryDaily re-checks Named reviewerNothing published without you

01 Six sources, read for you

why six

No single source is complete. A legal page will not tell you what engineering switched on last quarter; a header will not tell you about payroll.

Your published legal pages, your DNS and mail records, your response headers — a content-security-policy often enumerates every third party your product talks to — your consent tooling, any list you already keep, and your contracts. Each is read separately and reconciled.

02 Read your own lists

Send whatever you already keep — a vendor spreadsheet, a procurement export, a CSV somebody maintains by hand, a DPA annex. We reconcile it against everything discovered rather than asking you to choose which one is right.

Anything you supply is marked as told to us rather than observed, and that distinction is load-bearing: an entity we could never see from outside is never later reported as having disappeared.

Payroll, HR and data warehouses have no public footprint at all. Those only ever reach the list because you put them there.

03 Deciding what is in scope

the judgement a machine cannot make

A marketing tag on your website is not a sub-processor under your DPA. Deciding which is which is the expensive part, and it is the part you are buying.

Every candidate is classified as touching product data, infrastructure, or the website. A named reviewer makes that call, records it, and you see who decided before anything is published.

04 Your register page

Published at /register/yourcompany.com, current to the day, with every entity, its purpose, where it processes and a dated history going back to the day you started.

Each publication is a snapshot, not a pointer. Version 3 stays readable after version 4 exists, so nobody can quietly rewrite what the world saw last March — which is exactly the behaviour this product exists to catch elsewhere.

05 Embed it on your own site

One line, wherever you want it — your legal page, your trust centre, your docs.

your page
<div data-subprocessor-list></div>
<script src="https://subprocessor.org/embed/yourcompany.com.js" defer></script>

Rendered server-side, so there is no fetch, no CORS round trip and no empty table while it loads. It uses scoped inline styles rather than injecting our stylesheet into your page.

Or take the JSON and render it yourself — /v1/register/yourcompany.com, no key required.

06 Customer notices, in your name

the part that meets the obligation

Publishing a change is not telling anyone. Article 28 expects your customers to be informed.

Your customers subscribe to your register page. When you approve a change, the email goes out saying what actually moved — entity, purpose, country — not "something changed, log in to see". Double opt-in, one-click unsubscribe, and nothing is ever sent before you approve.

The notice also states plainly that it records what was published, and that whether a notice period applies comes from the reader's contract with you rather than from us.

07 Evidence packs

Pick a date range and get four files: the list as it stood at the end date, every change in the period, a printable report, and a manifest carrying a SHA-256 of each file and the ledger head at the moment of generation.

That last part is what makes it checkable rather than merely official-looking — an auditor can confirm months later that it has not been quietly regenerated with different contents.

No PDF is generated. Print the report from your own browser and you get a better document than we would render, and the CSVs are the machine-readable copy.

08 The decision log

the half auditors actually ask for

Detection without a recorded decision is half an answer. "What did you do about it?" is the follow-up question, every time.

Every change carries what was decided — accepted, dismissed, escalated — who decided it, and when, alongside the evidence they were looking at. Dismissals are permanent and recorded, so the same item is never raised twice.

09 Verify us rather than trust us

Every check, change and decision is appended to a hash-chained ledger. Each row carries the hash of the row before it, so an entry cannot be altered or back-dated without breaking every row that follows.

The verification endpoint is public and unauthenticated: you, your auditor, or a customer of yours can check a record without an account and without asking us.

no key needed
curl https://subprocessor.org/v1/ledger/<row hash>

10 Daily upkeep

Every source found during discovery is re-read daily. Presentation churn is stripped before anything is compared, so a rebuilt page or a reordered table cannot look like a change. What survives goes to a reviewer, then to your queue with the evidence attached.

Nothing is published and no customer is emailed while it sits there.

Measured false-positive rate: 0.6%, one in 160 harmless edits. A noisy detector gets muted, and then it protects nobody. How we measure that.

11 Watching the vendors you depend on

The same engine aimed outward. Add the companies whose lists you rely on and we read what each one publishes — usually before their own notice email reaches you, and sometimes when it never does.

Where you have given us the DPA and a reviewer has confirmed the notification clause, a change starts a countdown against your contract. Where we have no confirmed clause we open nothing, because a standard 30-day default shown beside a real date would be indistinguishable from a legal claim we cannot support.

12 The notice inbox

a number nobody else can produce

The vendor knows when they emailed. We know when their page moved. You are the only party holding both, which is exactly why this figure does not exist today.

Forward the notices your vendors send you. Each one is lined up against the day we saw that vendor's list change, and the distance is recorded — per notice, and as an average across your suppliers.

A gap is a measurement, not an accusation. Whether a notice period was met depends on your contract with them, not on our arithmetic. What we give you is the dated evidence to have that conversation with something in your hand.

Pasting a forwarded email works today. A dedicated forwarding address per account is wired and waiting on the mail route.

13 Fourth-party chains

Your vendors have vendors. Because watching already stores what each one publishes, the tier beneath them is data we hold rather than a separate exercise — and any of those you also watch becomes a provider in its own right, with its own tier below it.

the finding is not the tree

It is that eleven of your suppliers ultimately rest on one company. Reviewing each provider separately never surfaces that, because individually they all look fine.

The export is register-of-information shaped, not a register. Contract values, criticality and the classification of critical or important functions are yours to supply, and we do not invent columns we cannot fill honestly.

Where a provider publishes no list, the branch stops and says so. A gap drawn as an empty box reads as "nothing beneath them", which is a different and much more dangerous claim.

All of it starts with one domain.

Free discovery, a named reviewer, and nothing published until you say so.