Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Add Sub-Processors

Prev Next

Who can use this feature

  • Supported on Foundation, Growth, and Scale plans

Learn how to add, edit, and delete sub-processors on your Trust Portal.

What are Sub-Processors?

Sub-processors are third-party vendors your organization uses to deliver products and services, such as cloud storage providers, email services, payroll processors, analytics tools, etc. These vendors handle sensitive customer data on your behalf.

Scrut offers a dedicated section on your Trust Portal to showcase your sub-processors (aka vendors). You can use this section to list third-party vendors you use to deliver your services. This helps to nurture stakeholder trust, support compliance efforts, demonstrate transparency, and enhance customer confidence.

Add Sub-Processors to Your Trust Portal

  1. Sign in to Scrut and navigate to Trust → Trust Vault using the left side panel.

  2. Click the Overview tab.

  3. Scroll to the Sub-Processors section and click the Add Sub-Processor button.

  4. In the dropdown, search and select vendors from your existing vendor list. These are vendors already added to your Scrut organization that you want to publicly display as sub-processors on your Trust Portal.

    Note: You can select and add multiple sub-processors.

  5. To add a new vendor that's not in the list:

    • Type the vendor name in the search field

    • Click the +Create [Vendor Name] button that appears

    • Enter the vendor Name, select a Category, and choose relevant Entities

    • Click Add

    Note:

    New vendors created here are automatically added to your vendor list in Risk → Vendors for ongoing vendor management.

  6. Click Save and Continue.

  7. For each selected sub-processor, provide the following information:

    • Display Name (required): How the vendor appears on your Trust Portal

    • Website (required): The vendor's official URL

    • Location (required): Geographic location for compliance tracking

    Pro Tip!

    You can add logos and descriptions later by editing the sub-processor.

  8. Click Save. Your sub-processors are now visible in the Trust Vault.

  9. Click the View Trust Portal button at the top of the Overview tab to see how the sub-processors appear on your public Trust Portal.

Sub-Processors on Scrut Trust Portal

Edit Sub-Processor Details

You can update sub-processor information at any time to keep your Trust Portal up to date.

  1. Go to Trust → Trust Vault → Overview.

  2. Scroll to the Sub-Processors section and click the sub-processor you want to edit.

  3. Click the Edit icon in the side drawer.

  4. Update any of the following details:

    • Display Name: How the sub-processor appears publicly

    • Website: Official vendor URL

    • Logo: Upload the vendor's logo (JPEG or PNG, max 2 MB)

    • Location: Geographic location for compliance purposes

    • Description: A brief description of the vendor's role, services, and relevant certifications or compliance standards

    Pro Tip!

    A clear description helps stakeholders understand why you use this vendor and what data it handles.

  5. Click Save to save your changes to the Trust Portal.

Remove Sub-Processors

When you no longer work with a vendor, remove them from your Trust Portal to keep information accurate.

  1. Go to Trust → Trust Vault → Overview.

  2. Scroll to the Sub-Processors section and click the sub-processor you want to remove.

  3. Click the Delete icon in the side drawer.

  4. Confirm the deletion.

Note:

Removing a sub-processor only removes it from your public Trust Portal. The vendor remains in your internal vendor list (Risk → Vendors) for record-keeping purposes.

FAQs


1: What's the difference between a vendor and a sub-processor?

All sub-processors are vendors, but not all vendors are sub-processors. Vendors are any third-party companies you work with, tracked internally in Scrut. Sub-processors are the specific vendors you choose to publicly display on your Trust Portal because they handle customer data.

2: Will my customers be notified when I add or remove sub-processors?

No, currently Scrut doesn't automatically notify stakeholders of changes. You should communicate significant changes to sub-processors directly to your customers, especially if required by your contracts or privacy policies.

3: When should I update sub-processor information?

Update your sub-processors whenever:

  • You start or stop working with a vendor

  • A vendor changes their name, location, or services

  • You need to add compliance certifications or updated descriptions

4: Can I bulk add sub-processors?

Yes. When adding sub-processors, you can select multiple vendors at once.

5: What happens to deleted sub-processors?

When you delete a sub-processor from your Trust Portal, it only removes the public listing. The vendor record remains in Risk → Vendors for your internal tracking and compliance history.