RedHub AIRedHub AI
Tool Gate · How it works

How the roll-up gate works

How the Vendor Data-Flow Register gate works

This tool grades every vendor, AI tool, and sub-processor that touches your data. It reads 6 vendor flows and rolls them into one verdict — the worst, never the average — then a gate that can only make it worse.

The 6 vendor flows

01F3 · OpenAI APIfix firstregulated · cross-border · no DPA at allUNVETTED
02F2 · HubSpotpersonal · missing sub-processor disclosureGAP
03F1 · Striperegulated · cross-border · fully documentedDOCUMENTED
04F4 · Datadogpersonal · cross-border · fully documentedDOCUMENTED
05F5 · Notionlow sensitivity · fully documentedDOCUMENTED
06F6 · Acme Analyticsno sensitive data · purpose recordedDOCUMENTED
REGISTER COMPLETE
every vendor flow is documented
GAPS TO CLOSE
worst flow is a paperwork gap, not a missing DPA
NOT DEFENSIBLE
a personal-or-regulated flow has no DPA at all
Regulated-unvetted · worsen-only

A personal-or-regulated-sensitivity flow with no DPA at all is UNVETTED regardless of what else is documented - and one UNVETTED flow at or above the personal-sensitivity floor holds the whole register at NOT DEFENSIBLE, whatever share of vendors are otherwise documented.

NOT DEFENSIBLE

Why: Four of six vendor flows are fully documented and one - HubSpot - is only missing its sub-processor disclosure. But the OpenAI API flow is cross-border and regulated-sensitivity with no DPA in place at all, so it's UNVETTED. Register status is the worst flow, never the average, so it reads NOT DEFENSIBLE at 67% documented. 1 of 6 flows UNVETTED · 67% documented · worst-not-average.

Fix firstF3, the OpenAI API flow - get a DPA in place first; a regulated cross-border flow with zero data-protection paperwork is what trips the gate, not the missing retention or sub-processor detail on its own.

No single vendor flow is the crisis — the clustering is. The roll-up takes the worst, the gate escalates when trouble compounds, and it names the one thing to fix first. Grades the flow attributes you record against a required-controls checklist; it is not a legal assessment. Confirm data-processing obligations with your privacy or compliance counsel.