GUIDE

Tracking Stripe subprocessor changes

Where Stripe publishes its service providers, why your DPA and your SOC 2 program care when the list moves, and how to track it by hand or with proof.

01The page

Where Stripe publishes its subprocessors.

Stripe lists the service providers that process customer data at stripe.com/legal/service-providers. It is a table of entities, updated in place, with no changelog, no diff view, and no guarantee of an announcement when it changes. If Stripe processes payments for you, this page is part of your compliance surface whether you watch it or not.

02Why it matters

Your DPA probably promises you noticed.

Two obligations hang off this one page. Your DPA chain: if your own customers' data processing agreements flow down subprocessor commitments, a new entity in Stripe's list can be a new entity in yours, sometimes with an objection window that starts when the change is published, not when you happen to see it. And your vendor-monitoring control: SOC 2 CC9.2 and ISO 27001's supplier controls expect ongoing monitoring of exactly this kind of change, with evidence. A quarterly glance satisfies neither, because the page changes in place and holds no history. The full control walkthrough is in SOC 2 vendor monitoring, actually performed.

03By hand

Tracking it manually.

The workable manual method: save a dated capture of the page on a fixed schedule, diff each capture against the last, and log the review somewhere with timestamps you cannot edit. web.archive.org helps reconstruct the past when you start late, though its snapshot coverage is whatever it happens to be. The failure modes are the usual ones: the schedule slips, the diff is eyeballed, the log is a spreadsheet, and a change that appears and disappears between captures never existed.

04With proof

What Dormouse does with this page.

Dormouse fetches the list every 12 hours, extracts the table as a set (so a reordering is not a change and an added or removed entity is), alerts you with the exact diff when it moves, and records every check in a tamper-evident audit trail. When your auditor asks how you monitor Stripe, the answer is a monthly report showing every look, every change, and every gap, verifiable offline. The same watch covers thirteen more pre-tuned vendors, AWS and Google Cloud through Okta and Datadog, and any vendor page with a URL.

A subprocessor list with no changelog is a compliance obligation with no memory. The watching has to be the memory, and the memory has to be provable.

See it on your own vendors: send the list, get a free baseline report. No card, no call.