No third-party dependency without rights, security and exit evidence · Universal Apex Protected L-9.0 · 2026-07-23
Vendor, Model and Subprocessor Governance
Supply-chain rule. A model, API, dataset, cloud, advisor or subcontractor is not admitted because it is reputable or convenient. Contract, rights, security, location, change and exit evidence must pass.
Admission dossier
- legal identity, ownership, control, sanctions and conflict screening;
- service and data-flow description, processing roles and locations;
- licence, training, output, feedback, confidentiality and intellectual-property rights;
- security posture, incident history, vulnerability process and audit evidence;
- subprocessor chain, cross-border transfers and government-access exposure;
- model documentation, limitations, evaluation, monitoring and change notices;
- business continuity, portability, escrow where appropriate, termination and deletion;
- insurance, indemnity, liability, service levels and regulatory cooperation;
- approved use cases, prohibited data, tool permissions and human-approval thresholds.
Material-change gate
A provider, model, data, location, ownership, terms, subprocessor, security or capability change triggers re-review before expanded use. Silent provider changes may require suspension.
Exit doctrine
Maintain data export, configuration records, replacement options, deletion evidence, credential revocation and continuity plans so the institution is not captive to an unreviewed dependency.