Tool Gate · How it works
How the Vendor & Sub-Processor Data-Flow Register gate works
How the AI Vendor & Sub-Processor Data-Flow Register grades 6 vendor data flows on required governance attributes: a regulated-unvetted gate forces any regulated-data flow with no DPA to NOT DEFENSIBLE, and the register reads worst-not-average — which is how one flow with no DPA makes the whole 67%-documented register NOT DEFENSIBLE.
How the gate works
This tool grades every vendor, AI tool, and sub-processor that touches your data. It reads 6 vendor flows and rolls them into one verdict — the worst, never the average — and then a gate that can only make it worse.
The 6 vendor flows
| Vendor flow | Verdict |
|---|---|
| F3 · OpenAI APIfix first | UNVETTEDregulated · cross-border · no DPA at all |
| F2 · HubSpot | GAPpersonal · missing sub-processor disclosure |
| F1 · Stripe | DOCUMENTEDregulated · cross-border · fully documented |
| F4 · Datadog | DOCUMENTEDpersonal · cross-border · fully documented |
| F5 · Notion | DOCUMENTEDlow sensitivity · fully documented |
| F6 · Acme Analytics | DOCUMENTEDno sensitive data · purpose recorded |
The verdict bands
A personal-or-regulated-sensitivity flow with no DPA at all is UNVETTED regardless of what else is documented - and one UNVETTED flow at or above the personal-sensitivity floor holds the whole register at NOT DEFENSIBLE, whatever share of vendors are otherwise documented.
In the worked sample it reads NOT DEFENSIBLE — Four of six vendor flows are fully documented and one - HubSpot - is only missing its sub-processor disclosure. But the OpenAI API flow is cross-border and regulated-sensitivity with no DPA in place at all, so it's UNVETTED. Register status is the worst flow, never the average, so it reads NOT DEFENSIBLE at 67% documented. The one thing to fix first: F3, the OpenAI API flow - get a DPA in place first; a regulated cross-border flow with zero data-protection paperwork is what trips the gate, not the missing retention or sub-processor detail on its own..
Common questions
Can every vendor flow look survivable on the How the Vendor Data-Flow Register gate works and the company still read NOT DEFENSIBLE?
Yes. The roll-up takes the worst of 6 vendor flows — never the average — then a worsen-only gate, the Regulated-unvetted gate, escalates when trouble clusters. In the worked sample it reads NOT DEFENSIBLE because four of six vendor flows are fully documented and one - HubSpot - is only missing its sub-processor disclosure. But the OpenAI API flow is cross-border and regulated-sensitivity with no DPA in place at all, so it's UNVETTED. Register status is the worst flow, never the average, so it reads NOT DEFENSIBLE at 67% documented.
What is a worsen-only gate?
A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-set of survivable lines, because a single disqualifying gap shouldn't hide behind an average of the healthy ones. The tool also names the one thing to fix first — here, "F3, the OpenAI API flow - get a DPA in place first; a regulated cross-border flow with zero data-protection paperwork is what trips the gate, not the missing retention or sub-processor detail on its own.".
Grades the flow attributes you record against a required-controls checklist; it is not a legal assessment. Confirm data-processing obligations with your privacy or compliance counsel.
Embed this diagram
Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.
Interactive — renders the live diagram
<iframe src="https://redhub.ai/visuals/tool/vendor-data-flow-register.html" title="How the Vendor & Sub-Processor Data-Flow Register gate works — RedHub AI" width="760" height="1797" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/vendor-data-flow-register">How the Vendor & Sub-Processor Data-Flow Register gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>Image + link — a static picture for any blog
<a href="https://redhub.ai/visuals/tool/vendor-data-flow-register"><img src="https://redhub.ai/visuals/tool/vendor-data-flow-register-share.png" alt="Diagram of the Vendor & Sub-Processor Data-Flow Register: six vendor flows rolled up worst-not-average, a regulated-unvetted gate, and the register reading NOT DEFENSIBLE on one flow with no DPA." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>This is how AI Vendor & Sub-Processor Data-Flow Register works. More diagrams in the Visual Field Guide.