EZBudget™
Third Party Risk Management Policy
Defined vendor / third-party risk management with technical and administrative controls.
1. Policy Statement
Deseo Developers LLC maintains a third-party risk management program for vendors and subprocessors that process Finducation customer data, host production systems, or provide material integrations (including financial data providers). Vendors are selected, contracted, monitored, and reviewed using administrative and technical controls proportionate to risk.
2. Scope
- Cloud hosting and serverless compute providers
- Authentication and database providers
- Payment processors
- Financial account aggregation / API partners (e.g., Plaid)
- Other vendors with access to production systems, secrets, or personal data
3. Subprocessor Inventory
| Vendor | Purpose | Data / Access Involved |
|---|---|---|
| Netlify | Hosting, CDN, serverless functions, deploy pipeline | Application traffic, function logs, environment secrets |
| Supabase | Authentication, database, storage | User accounts, application data, auth events |
| Stripe | Billing and subscriptions | Payment metadata; card data handled by Stripe |
| Plaid | Bank account linking and transaction data for budgeting features | Access tokens, institution metadata, transaction data used by EZBudget |
| GitHub | Source control | Source code and CI/CD metadata (no production customer PII in repo by policy) |
The Privacy Policy processor list is kept consistent with this inventory.
4. Vendor Intake Controls
Before adopting a new material vendor, engineering/security evaluates:
- Business need and data categories involved
- Security posture (trust center, SOC 2/ISO reports, security documentation where available)
- Contractual terms: confidentiality, data processing, breach notification, subprocessors
- Technical integration risk (OAuth scopes, token storage, webhook authenticity, least privilege)
- Exit / data deletion path
High-risk vendors (financial data, auth, primary datastore) require documented approval by the authorized owner before production use.
5. Technical Controls
- API keys and access tokens stored in environment secrets, not source control.
- Least-privilege credentials and scoped tokens for each integration.
- TLS for data in transit to vendor APIs.
- Webhook signature verification where supported (e.g., Stripe).
- MFA on vendor administrative consoles (EZB-MFA-002).
- Application logging of material integration failures without logging secrets (EZB-LOG-001).
6. Administrative Controls
- Written agreements / platform terms accepted for each material vendor.
- Access to vendor dashboards limited to authorized maintainers.
- Vendor inventory reviewed at least annually.
- Material vendor security incidents are handled under the Incident Response Policy (EZB-IR-001).
7. Ongoing Monitoring
- Monitor vendor status pages and security notices for material outages or incidents.
- Reassess vendors when expanding data use (e.g., new Plaid products) or changing hosting architecture.
- Remove unused integrations and revoke orphaned credentials promptly.
8. Periodic Review
- This policy and the subprocessor inventory are reviewed at least annually.
- DPAs / trust documentation are revisited during annual review for high-risk vendors.
9. Related Documents
- Finducation Privacy Policy
- Information Security and Governance Policy (EZB-ISG-001)
- Incident Response Policy (EZB-IR-001)
- Access Control Policy (EZB-ACM-001)
- Logging and Monitoring Policy (EZB-LOG-001)
10. Approval
Approved By: Deseo Developers LLC — Authorized Representative
Date: July 22, 2026
Contact: contact@deseodevelopers.com