/SLASHLOGIXX TRUST
Operating Policy

Vendor & Subprocessor Management

Version 1.0 · Effective 2026-05-19 · Owner: Security

1. Purpose

Every third party that touches the Spark platform or customer data is itself a piece of our security posture. This policy defines how SlashLogixx selects, contracts with, monitors, and offboards those parties.

2. Scope

Applies to any external service or company that processes, stores, transmits, hosts, or has logical access to customer data, production infrastructure, source code, or administrative tooling. The current public list is maintained on the Subprocessors page.

3. Onboarding Review

Before a new vendor is added to a production data path, Security completes a documented review covering:

4. Contractual Posture

Vendors that process Confidential or Restricted customer data must be under contract that includes, at minimum:

5. Customer Notification of Subprocessor Changes

6. Monitoring

7. Concentration & Continuity

8. Offboarding

9. AI Subprocessors

External AI providers that process customer data are treated as Restricted-data subprocessors. SlashLogixx selects only providers with zero-retention, no-training contractual commitments for production traffic, and configures the integration accordingly. The current AI subprocessor set is shown on the Subprocessors page.

10. Customer Veto

Customers under a signed DPA may, with notice, object to the use of a specific new subprocessor for their data. SlashLogixx will work in good faith to identify an alternative or, where no alternative exists, discuss the customer's options including termination per the master agreement.