← Q&A knowledge base
Product Updated 2026-09-14

What does Maditon do about my suppliers?

Maditon keeps a register of the services your company depends on and reads each supplier's published legal documents — privacy policy, terms, data processing agreement, sub-processor list, security page — reporting what they say and what they leave out, with every finding quoting its source passage. It then watches those documents and tells you when they change.

Two obligations make this ordinary work rather than a nice-to-have. GDPR Article 28 says you may only use a processor who gives sufficient guarantees, and Article 30 says you keep a record of your processing — including who processes what on your behalf. NIS2 Article 21 adds supply-chain security for the entities it covers. Both turn “which services do we use, and what did they promise” into a question somebody will eventually ask you in writing.

What it reads. Only what the supplier published: the privacy policy, the terms, the data processing agreement, the sub-processor list, the security page. You can also upload something a supplier sent you privately — a signed DPA, a completed questionnaire — and that stays private to your company.

What it produces. Findings, each one quoting the sentence it came from, grouped by how much they ought to worry you. A finding is a question to put to the supplier. Where the documents simply do not say, the result is “not addressed” rather than a failure — silence is not a breach, it is a gap in what you know.

What it refuses to do. It does not certify anybody. No reading of a published web page can establish that a company actually does what its page says, and a tool that said otherwise would be selling false comfort.

The register is also what the rest of the product runs on: a purchase compares candidates in it, a customer questionnaire is answered from it, and the sub-processor list you publish is derived from the suppliers you marked as in use.

Related API endpoints

GET /api/vendors bearer

The organisation's supplier register.

GET /api/vendor-changes bearer

Everything that changed in the register, newest first.

Base URL https://api.maditon.app · full specification at openapi.json

Regulation references

Read next

A free Solo account runs a real classification on one of your own systems — no card, no sales call.

Run a free classification