Tool Gate · How it works

How the Vendor & Sub-Processor Data-Flow Register gate works

How the AI Vendor & Sub-Processor Data-Flow Register grades 6 vendor data flows on required governance attributes: a regulated-unvetted gate forces any regulated-data flow with no DPA to NOT DEFENSIBLE, and the register reads worst-not-average — which is how one flow with no DPA makes the whole 67%-documented register NOT DEFENSIBLE.

How the gate works

This tool grades every vendor, AI tool, and sub-processor that touches your data. It reads 6 vendor flows and rolls them into one verdict — the worst, never the average — and then a gate that can only make it worse.

The 6 vendor flows

Vendor flowVerdict
F3 · OpenAI APIfix firstUNVETTEDregulated · cross-border · no DPA at all
F2 · HubSpotGAPpersonal · missing sub-processor disclosure
F1 · StripeDOCUMENTEDregulated · cross-border · fully documented
F4 · DatadogDOCUMENTEDpersonal · cross-border · fully documented
F5 · NotionDOCUMENTEDlow sensitivity · fully documented
F6 · Acme AnalyticsDOCUMENTEDno sensitive data · purpose recorded

The verdict bands

REGISTER COMPLETE
every vendor flow is documented
GAPS TO CLOSE
worst flow is a paperwork gap, not a missing DPA
NOT DEFENSIBLE
a personal-or-regulated flow has no DPA at all
Regulated-unvetted · worsen-only

A personal-or-regulated-sensitivity flow with no DPA at all is UNVETTED regardless of what else is documented - and one UNVETTED flow at or above the personal-sensitivity floor holds the whole register at NOT DEFENSIBLE, whatever share of vendors are otherwise documented.

In the worked sample it reads NOT DEFENSIBLEFour of six vendor flows are fully documented and one - HubSpot - is only missing its sub-processor disclosure. But the OpenAI API flow is cross-border and regulated-sensitivity with no DPA in place at all, so it's UNVETTED. Register status is the worst flow, never the average, so it reads NOT DEFENSIBLE at 67% documented. The one thing to fix first: F3, the OpenAI API flow - get a DPA in place first; a regulated cross-border flow with zero data-protection paperwork is what trips the gate, not the missing retention or sub-processor detail on its own..

Common questions

Can every vendor flow look survivable on the How the Vendor Data-Flow Register gate works and the company still read NOT DEFENSIBLE?

Yes. The roll-up takes the worst of 6 vendor flows — never the average — then a worsen-only gate, the Regulated-unvetted gate, escalates when trouble clusters. In the worked sample it reads NOT DEFENSIBLE because four of six vendor flows are fully documented and one - HubSpot - is only missing its sub-processor disclosure. But the OpenAI API flow is cross-border and regulated-sensitivity with no DPA in place at all, so it's UNVETTED. Register status is the worst flow, never the average, so it reads NOT DEFENSIBLE at 67% documented.

What is a worsen-only gate?

A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-set of survivable lines, because a single disqualifying gap shouldn't hide behind an average of the healthy ones. The tool also names the one thing to fix first — here, "F3, the OpenAI API flow - get a DPA in place first; a regulated cross-border flow with zero data-protection paperwork is what trips the gate, not the missing retention or sub-processor detail on its own.".

Grades the flow attributes you record against a required-controls checklist; it is not a legal assessment. Confirm data-processing obligations with your privacy or compliance counsel.

Embed this diagram

Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.

Interactive — renders the live diagram

<iframe src="https://redhub.ai/visuals/tool/vendor-data-flow-register.html" title="How the Vendor & Sub-Processor Data-Flow Register gate works — RedHub AI" width="760" height="1797" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/vendor-data-flow-register">How the Vendor & Sub-Processor Data-Flow Register gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>

Image + link — a static picture for any blog

<a href="https://redhub.ai/visuals/tool/vendor-data-flow-register"><img src="https://redhub.ai/visuals/tool/vendor-data-flow-register-share.png" alt="Diagram of the Vendor & Sub-Processor Data-Flow Register: six vendor flows rolled up worst-not-average, a regulated-unvetted gate, and the register reading NOT DEFENSIBLE on one flow with no DPA." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>

Download the image: dark · light

This is how AI Vendor & Sub-Processor Data-Flow Register works. More diagrams in the Visual Field Guide.