Skip to main content
Trust Center

Subprocessors and Trust Boundary

PrismCDM is designed so customer data remains inside a controlled trust boundary. Where third-party providers are required to operate the platform, they process customer data only for the specific service they provide, under contractual, technical, and organizational safeguards consistent with PrismCDM's security, privacy, and Source Fidelity commitments.

1. The trust boundary

A subprocessor is a third party that processes customer data on PrismCDM's behalf to support the operation of the platform. Subprocessors are bound by written agreements requiring confidentiality, security, and processing limitations equivalent to PrismCDM's own commitments to customers.

A subprocessor never becomes the system of record for customer clinical data. PrismCDM remains the authoritative system of record for platform-managed data, provenance, and integrity anchors.

Subprocessors are distinct from independent third parties a customer might integrate with directly. Integration partners chosen by the customer are governed by the customer's relationship with that partner, not by this list.

2. Subprocessor categories

The current categories, the purpose each serves, the categories of data each touches, and the trust-boundary properties enterprise security teams expect to confirm.

CategoryPurposeCustomer DataTenant IsolationAI Training
Cloud infrastructureHosting and storageYesYesN/A
Identity and authenticationAuthenticationLimited identity attributesYesNo
Email and transactional messagingNotificationsEmail metadataYesNo
AnalyticsUsage metricsConsent controlledYesNo
AI inference providersAI features within tenantCustomer-authorized prompts onlyYesNo
Customer supportTicketing and operational supportLimited support metadataYesNo
Observability and security operationsLogging, monitoring, SecOpsOperational telemetryYesNo

The detailed live list (named providers, processing region, data categories, security attestations) is shared during the Compliance Review under NDA.

3. AI providers within the trust boundary

AI providers receive only the information required to perform the requested inference. Customer data is not used to train shared foundation models without explicit customer consent. AI-generated outputs remain bound to the customer's tenant and are governed by the Source Fidelity controls described at /trust/responsible-ai.

4. What subprocessors cannot do

The trust boundary is defined as much by what subprocessors cannot do as by what they do.

  • Cannot access customer data except as necessary to provide their contracted service.
  • Cannot use customer data to train shared AI models without explicit customer consent.
  • Cannot disclose customer data except as permitted by contract or required by law.
  • Cannot change customer data or provenance records on behalf of PrismCDM.
  • Cannot redefine the trust model: provenance, evidence classification, and regulated execution remain under PrismCDM control.

5. Public protocol sources

Public protocol repositories such as ClinicalTrials.gov are treated as public-source evidence under the Source Fidelity architecture. Public sources are evidence inputs, not subprocessors, and are never combined with customer-source data in a manner that changes source classification.

6. Customer-controlled integrations

Integrations the customer establishes directly are controlled by the customer, not by PrismCDM. The distinction matters when reviewing third-party access to customer data.

TypeControlled ByInside PrismCDM Trust Boundary
PrismCDM subprocessorsPrismCDMYes (with the controls described above)
Customer integrationsCustomerOutside (governed by customer agreements)
Public protocol sourcesNeitherOutside (treated as public-source evidence)

7. Trust boundary summary

What stays inside the PrismCDM trust boundary, what crosses it under controlled conditions, and how each is governed.

CategoryInside Trust BoundaryOutside Trust Boundary
Customer data
Provenance records
Audit trail
Trial Intelligence
Source classification
Identity verificationLimited identity attributes only
Email deliveryEmail metadata only
AI inferenceCustomer-authorized prompts only
Cloud hostingEncrypted storage and compute

8. How changes are communicated

Material changes to the subprocessor list are communicated through the platform or by email to customers where required by the applicable commercial agreement. The notice period and customer right to object are governed by the executed Data Processing Agreement (see /trust/dpa).

9. Customer right to object

Customers operating under an executed commercial agreement may object to a new subprocessor on reasonable grounds. The objection process and the resolution path are governed by the executed Master Services Agreement and the Data Processing Agreement. PrismCDM works in good faith to find a resolution, including by adjusting the subprocessor arrangement or, where necessary, providing the customer with a termination right with respect to the affected service.

10. Subprocessor due diligence

Before a new subprocessor is introduced, PrismCDM reviews its security posture, data handling commitments, regulatory position, and contractual undertakings. Existing subprocessors are reviewed periodically to confirm their commitments remain consistent with our customers' expectations and our own.

11. PrismCDM does not outsource trust

Third-party providers supply infrastructure and supporting services; provenance, evidence classification, auditability, and regulated execution remain under PrismCDM's architectural control.

12. Related Trust Center documents

Version
1.0
Effective Date
July 2026
Last Updated
July 2026