Third Parties

Third-Party Supplier Management

How we assess, select, and keep track of the suppliers that sit behind the solutions we deliver.

Trust & Compliance Centre · Last reviewed: September 2025

At a glance

Do you conduct due diligence on your third-party suppliers (hosting, plugins, integrations)? Yes Suppliers are assessed before adoption and reviewed periodically
Do you maintain a register of all third-party suppliers with access to customer data? Yes Maintained internally; shared with customers under NDA

Due diligence before adoption

Before a third-party service, library, or platform is adopted into our delivery stack or into a customer solution, it is assessed for:

  • Security posture — published certifications (ISO 27001, SOC 2), security documentation, breach history, and authentication options (MFA support is expected for anything holding credentials or data).
  • Data protection — where data is stored and processed, whether UK/EEA residency is available, and whether the supplier offers UK GDPR-compliant processing terms (Article 28 data processing agreements and, for transfers outside the UK, appropriate safeguards such as the UK Addendum or International Data Transfer Agreement).
  • Commercial stability — maturity, support arrangements, and exit options if the supplier fails or is withdrawn.
  • Open-source components — licence compatibility, maintenance activity, and known-vulnerability status (see Secure Development & Change Management for dependency management).

Suppliers already embedded in an engagement are reviewed periodically, and reassessed on significant events — a breach disclosure, an acquisition, or a material change of terms.

Principal suppliers

Our principal third-party suppliers are deliberately few and well-established:

  • Microsoft Azure — cloud hosting for customer solutions and our own services, in UK regions (see Hosting & Data Residency).
  • Microsoft development platforms — source control, DevOps pipelines, and delivery tooling.
  • Transactional email and anti-abuse services — used for contact form delivery and bot protection on our website.
  • Vanta — trust-management platform providing continuous, automated compliance monitoring of our estate (see Certifications & Standards).

Engagement-specific suppliers (for example, a payment provider or analytics platform chosen for a customer's solution) are agreed with the customer and documented as part of that engagement.

Supplier register

We maintain a register of third-party suppliers, recording for each: the service provided, the categories of data it can access, its data storage location, the contractual terms in place, and the date of last review. Suppliers with access to customer data are flagged, and the register is the reference used when responding to customer due-diligence and sub-processor queries.

Register available on request

The full supplier register is confidential — publishing a complete map of suppliers and access levels would be useful to an attacker. Customers can request the register, or the subset relevant to their engagement, under NDA via hello@assemblysoft.com.

Back to the Trust & Compliance Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor