Subprocessors and Trust Boundary
PrismCDM is designed so customer data remains inside a controlled trust boundary. Where third-party providers are required to operate the platform, they process customer data only for the specific service they provide, under contractual, technical, and organizational safeguards consistent with PrismCDM's security, privacy, and Source Fidelity commitments.
1. The trust boundary
A subprocessor is a third party that processes customer data on PrismCDM's behalf to support the operation of the platform. Subprocessors are bound by written agreements requiring confidentiality, security, and processing limitations equivalent to PrismCDM's own commitments to customers.
A subprocessor never becomes the system of record for customer clinical data. PrismCDM remains the authoritative system of record for platform-managed data, provenance, and integrity anchors.
Subprocessors are distinct from independent third parties a customer might integrate with directly. Integration partners chosen by the customer are governed by the customer's relationship with that partner, not by this list.
2. Subprocessor categories
The current categories, the purpose each serves, the categories of data each touches, and the trust-boundary properties enterprise security teams expect to confirm.
| Category | Purpose | Customer Data | Tenant Isolation | AI Training |
|---|---|---|---|---|
| Cloud infrastructure | Hosting and storage | Yes | Yes | N/A |
| Identity and authentication | Authentication | Limited identity attributes | Yes | No |
| Email and transactional messaging | Notifications | Email metadata | Yes | No |
| Analytics | Usage metrics | Consent controlled | Yes | No |
| AI inference providers | AI features within tenant | Customer-authorized prompts only | Yes | No |
| Customer support | Ticketing and operational support | Limited support metadata | Yes | No |
| Observability and security operations | Logging, monitoring, SecOps | Operational telemetry | Yes | No |
The detailed live list (named providers, processing region, data categories, security attestations) is shared during the Compliance Review under NDA.
3. AI providers within the trust boundary
AI providers receive only the information required to perform the requested inference. Customer data is not used to train shared foundation models without explicit customer consent. AI-generated outputs remain bound to the customer's tenant and are governed by the Source Fidelity controls described at /trust/responsible-ai.
4. What subprocessors cannot do
The trust boundary is defined as much by what subprocessors cannot do as by what they do.
- Cannot access customer data except as necessary to provide their contracted service.
- Cannot use customer data to train shared AI models without explicit customer consent.
- Cannot disclose customer data except as permitted by contract or required by law.
- Cannot change customer data or provenance records on behalf of PrismCDM.
- Cannot redefine the trust model: provenance, evidence classification, and regulated execution remain under PrismCDM control.
5. Public protocol sources
Public protocol repositories such as ClinicalTrials.gov are treated as public-source evidence under the Source Fidelity architecture. Public sources are evidence inputs, not subprocessors, and are never combined with customer-source data in a manner that changes source classification.
6. Customer-controlled integrations
Integrations the customer establishes directly are controlled by the customer, not by PrismCDM. The distinction matters when reviewing third-party access to customer data.
| Type | Controlled By | Inside PrismCDM Trust Boundary |
|---|---|---|
| PrismCDM subprocessors | PrismCDM | Yes (with the controls described above) |
| Customer integrations | Customer | Outside (governed by customer agreements) |
| Public protocol sources | Neither | Outside (treated as public-source evidence) |
7. Trust boundary summary
What stays inside the PrismCDM trust boundary, what crosses it under controlled conditions, and how each is governed.
| Category | Inside Trust Boundary | Outside Trust Boundary |
|---|---|---|
| Customer data | ||
| Provenance records | ||
| Audit trail | ||
| Trial Intelligence | ||
| Source classification | ||
| Identity verification | Limited identity attributes only | |
| Email delivery | Email metadata only | |
| AI inference | Customer-authorized prompts only | |
| Cloud hosting | Encrypted storage and compute |
8. How changes are communicated
Material changes to the subprocessor list are communicated through the platform or by email to customers where required by the applicable commercial agreement. The notice period and customer right to object are governed by the executed Data Processing Agreement (see /trust/dpa).
9. Customer right to object
Customers operating under an executed commercial agreement may object to a new subprocessor on reasonable grounds. The objection process and the resolution path are governed by the executed Master Services Agreement and the Data Processing Agreement. PrismCDM works in good faith to find a resolution, including by adjusting the subprocessor arrangement or, where necessary, providing the customer with a termination right with respect to the affected service.
10. Subprocessor due diligence
Before a new subprocessor is introduced, PrismCDM reviews its security posture, data handling commitments, regulatory position, and contractual undertakings. Existing subprocessors are reviewed periodically to confirm their commitments remain consistent with our customers' expectations and our own.
11. PrismCDM does not outsource trust
Third-party providers supply infrastructure and supporting services; provenance, evidence classification, auditability, and regulated execution remain under PrismCDM's architectural control.
12. Related Trust Center documents
- Security:the architectural posture.
- Responsible AI Architecture:AI providers within the trust boundary.
- Data Processing Agreement:the legal framework.
- Business Associate Agreement:HIPAA-specific obligations.
- Privacy:privacy posture and data subject rights.
- Version
- 1.0
- Effective Date
- July 2026
- Last Updated
- July 2026