Vendor & Subprocessor Risk Management — postal.ID
postal.ID performs security and privacy due diligence before onboarding any subprocessor and maintains ongoing oversight.
Our Approach
- Pre-onboarding review — vendors are assessed for security certifications, encryption practices, access controls, and data processing terms before engagement.
- Contractual controls — Data Processing Agreements and security addenda are executed with all subprocessors handling personal data.
- Ongoing monitoring — subprocessors are reviewed periodically and upon any material change in scope or following a security incident.
A list of current subprocessors is maintained in the Data Processing Agreement.
Detailed vendor risk assessment criteria, scoring methodology, and internal review procedures are available under NDA upon request during procurement or due diligence.