サブプロセッサーとは?

サブプロセッサーとは、サービスの提供の一環として顧客データを処理するためにVerbumが起用するサードパーティ企業です。サブプロセッサーは、特定の機能を実行するために必要な範囲でのみデータを処理します。お客様は法務、プライバシー、調達レビューの一環として追加詳細を依頼できます。

セキュリティレビュー

詳細なサブプロセッサー情報はセキュリティレビュー中に提供できます。

Verbumは、クラウドインフラ、ホスティング、認証、モニタリング、決済、通信、AIインフラなどのサービスカテゴリ別にサブプロセッサーを管理しています。詳細なプロバイダー名、処理目的、地域情報は、適切な機密保持プロセスの下で、適格なお客様のエンタープライズセキュリティレビュー中に共有できます。

サブプロセッサーレビューは、DPA、security control review materials、security control mapping、privacy documentationとあわせて提供される場合があります。

レビューパッケージリクエストに応じて
  • プロバイダー名と目的
  • データカテゴリと処理コンテキスト
  • 利用可能な場合の地域情報
  • Data Processing Overview and subprocessors documentation
  • Security control review materials
  • security control mapping
  • Protected evidence materials

Subprocessor disclosure

This disclosure separates providers approved for public naming from additional provider categories available during qualified security, privacy or procurement review. It is not a complete deployment-specific provider list.

Stripe is disclosed for paid checkout and billing. AWS and Microsoft Azure are disclosed as deployment-specific or service-specific cloud providers: a customer deployment may use AWS, Azure or both for different approved service functions depending on architecture and region, and exact use is confirmed during qualified review. OpenAI is disclosed only where AI-assisted features are enabled for an approved workspace scope. Authentication, monitoring, analytics and support/procurement provider details remain available during qualified review until provider names, scope and regional details are approved for public disclosure.

PROCUREMENT VIEW

What this disclosure gives your vendor review team

Use the public table for named providers and policy links. Use the review-only table to identify provider categories that may require a qualified review path before provider names, regions or deployment-specific context can be shared.

  • Disclosure status
  • Review availability
  • Confidentiality requirement

Public providers

5 named providers

Provider names and approved policy links are listed below when public disclosure is approved.

Review-only categories

4 protected categories

Provider categories are visible publicly; confidential provider names remain available only through qualified review.

Review availability

Qualified review

Procurement, privacy and security teams can request deployment-specific provider context.

NDA availability

May apply

Sensitive provider details may require NDA or an appropriate confidentiality process.

Publicly disclosed providers

Public provider information is listed separately from service categories that require qualified review. Protected provider names remain available only through the qualified review path.

Public subprocessor disclosure for procurement review
Service categoryProviderPurposeData categoryRegion/locationStatusReview notePolicy link
PaymentsStripeSubscription billing and payment processing.Billing contact, payment method details, payment processor identifiers and subscription identifiers.Depends on Stripe processing and customer billing configuration.Publicly disclosed payment processorPublic page and qualified procurement review
Cloud infrastructureAmazon Web Services, Inc.Hosting, compute, storage, secrets management and platform resilience for deployments or services configured to use AWS.Customer workspace data, message records, audit events, operational metadata, secrets metadata and platform logs needed to operate the service.Deployment-specific AWS region; confirmed during qualified security or procurement review.Publicly disclosed cloud infrastructure providerPublic page and qualified security review
Cloud infrastructureMicrosoft CorporationMicrosoft Azure platform services used for cloud infrastructure and related service delivery for deployments or services configured to use Azure.Customer workspace data, message records, audit events, operational metadata and platform logs needed to operate the service.Deployment-specific Azure region; confirmed during qualified security or procurement review.Publicly disclosed cloud infrastructure providerPublic page and qualified security review
Email/communicationsMicrosoft CorporationAzure communications services used for operational messages, account notifications, support communications or security/procurement follow-up where configured.Business contact details, message metadata and communication content submitted through Verbum forms or operational workflows.Deployment-specific Azure communications region; confirmed during qualified privacy, security or procurement review.Publicly disclosed communications providerPublic page and qualified privacy review
AI processingOpenAIAI-assisted draft generation, summarization or routing support where OpenAI services are enabled for an approved workspace scope.Message context, prompts or inputs, generated drafts, workflow metadata and provider configuration context.Provider processing locations and transfer context are confirmed during qualified security or privacy review for the approved workspace scope.Publicly disclosed AI processing providerPublic page and qualified security review

Review-only categories

Additional providers available during qualified review. These categories identify provider areas that may apply to a deployment. Provider names, regional details and deployment-specific context are disclosed only through the qualified review path. No confidential provider name is published here.

Provider categories available during qualified review
Service categoryDisclosure statusPurposeData categoryRegion contextDeployment conditionReview availabilityConfidentiality requirementLast reviewed
AuthenticationReview-only categoryIdentity, access management, authentication workflows and SSO-related controls where configured.User profile data, workspace identifiers, access metadata and authentication events.Provider and regional details depend on workspace configuration and review scope.Conditional provider category. Applies only where authentication, identity or SSO tooling is configured for the applicable workspace.Available during qualified security reviewProvider details are available to qualified customers during security review, subject to the appropriate confidentiality process.June 19, 2026
Observability/security monitoringReview-only categoryPlatform reliability monitoring, diagnostics, security alerting and incident investigation support.Operational logs, security events, access metadata, error traces and limited diagnostic context.Deployment-specific processing and transfer details are reviewed under the security process.Conditional provider category. Applies only where monitoring, diagnostics, alerting or incident review tooling is configured for the deployment.Available during qualified security reviewProvider details are available to qualified customers during security review, subject to the appropriate confidentiality process.June 19, 2026
Analytics, where enabledReview-only categoryProduct usage analysis, conversion measurement and operational reporting where analytics is approved and enabled.Usage events, page or product interactions, device/browser context and non-sensitive operational metadata where enabled.Provider details are reviewed if analytics is enabled for the applicable environment.Not currently active on the public website without approved analytics provider configuration and consent gating.Available during qualified security review if analytics is enabledProvider details are available to qualified customers during security review when analytics is enabled, subject to the appropriate confidentiality process.June 19, 2026
Support/procurement toolingReview-only categoryCustomer support, vendor questionnaires, legal/security review workflow and procurement communications.Support tickets, procurement communications, legal/security review context and business contact details.Provider and region details may vary by review workflow and are shared through the qualified review process.Conditional provider category. Applies only where support, legal review or procurement workflow tooling is configured.Included in qualified security package when applicableProvider details are available to qualified customers during security review, subject to the appropriate confidentiality process.June 19, 2026

How we manage subprocessors

Verbum maintains a controlled subprocessor review process that supports privacy reviews under LGPD and GDPR-aligned data processing requirements.

  • Material subprocessors are reviewed for security and privacy relevance.
  • Subprocessors are documented for legal, privacy and procurement review.
  • Customer-facing providers are disclosed where applicable.
  • Enterprise customers can request additional details during security review.

最新情報の確認

Verbumがサブプロセッサーを追加、置換、または削除するにつれて、このリストは変更される場合があります。重要な変更の事前通知を行うよう努めています。

お客様はVerbumに対し、重要なサブプロセッサーの変更に関する問い合わせやDPAレビューのリクエストを行うことができます。

A fixed advance notice period or contractual objection right is stated only when defined by the applicable DPA, order form or approved legal policy.

  • June 19, 2026Added AWS, Microsoft Azure and OpenAI to the public subprocessor disclosure.
  • June 16, 2026Published initial public Stripe disclosure and qualified-review provider categories.

サブプロセッサー、調達、プライバシーレビューが必要ですか?

エンタープライズ評価では、サブプロセッサー、DPA条件、セキュリティ資料のレビューについてVerbumにお問い合わせください。