Skip to content

PCI DSS Pregunta 91 — Service Provider Agreements + Compliance Status + Shared Responsibility ​

CampoValor
SolicitanteJosé David Álvarez — QSA ControlCase
Pregunta"Para todos los proveedores de servicios terceros y socios comerciales identificados dentro del ámbito: (a) acuerdo de servicios vigente que cubra seguridad, disponibilidad, confidencialidad, integridad del procesamiento y/o privacidad para el manejo de la información cubierta; (b) estado actual de cumplimiento respecto a normativas/estándares de seguridad de datos aplicables; (c) lista de requisitos de seguridad que cada proveedor externo gestiona en su nombre; (d) acuerdos."
Fecha2026-06-16
Tipo de evidenciaInventario vendor + MSAs vigentes + compliance attestations + shared responsibility matrices per vendor + TMPL-014 tracker + sample agreement clauses
EstadoRESUELTO — Inventario completo de 11 vendors activos con acuerdo vigente. Cada uno con: MSA active, compliance attestation actual (PCI/SOC2/ISO 27k cuando aplica), PCI clause acknowledgement, shared responsibility matrix por requisito PCI. TMPL-014 v1.0 emitida como plantilla de tracking continuo.
Controles PCIReq 12.8.1 (lista TPSPs), 12.8.2 (written agreements), 12.8.3 (due diligence), 12.8.4 (monitor compliance), 12.8.5 (shared responsibilities)
Paquete adjuntoq91-vendor-agreements-20260616.tar.gz

Resumen ejecutivo: PCI DSS v4.0 Req 12.8 (5 sub-requisitos) exige para cada TPSP: (a) acuerdo escrito que cubra security + availability + confidentiality + integrity + privacy, (b) monitoreo del compliance status anualmente, (c) shared responsibility matrix documentada. Cumplimos con 11 vendors activos completamente documentados. Aclaración crítica (verificado visualmente 2026-06-16 en https://www.digitalocean.com/trust/certification-reports): DigitalOcean NO tiene AOC PCI DSS Level 1 Service Provider — tiene PCI-DSS SAQ-A (Zero-Footprint data policy) que cubre únicamente que DO no almacena/procesa/transmite CHD en su environment administrativo. Implicación: DO NO puede ser invocado como "PCI Service Provider" para Fintrixs. Sus attestations reales son: SOC 2 Type II + SOC 3 Type II by Schellman & Company, CIS Benchmarks, Global PRP Certification by Schellman, PCI-DSS SAQ-A (Zero-Footprint), CSA Self-Assessment Level 1 (16 domains, no third-party attested), GDPR + DPA executed. La delegación de PCI 9.x (físico) + 11.2 (wireless) a DO se basa en SOC 2 II by Schellman + CSA Self-Assessment + DPA (práctica aceptada por PCI SSC para cloud providers sin Level 1 SP AOC). (1) Vendors críticos con PCI DSS AOC dedicado: ControlCase (PCI DSS Level 1 SP AOC + SOC 2 II — vendor de QSA+ASV+IDR+PCIUA), Credibanco (PCI DSS Level 1 + Visa+Mastercard certified — acquirer Colombia); (2) Vendor crítico con SAQ-A + SOC 2 by Schellman: DigitalOcean (NO Level 1 SP — infra cloud); (3) Otros vendors críticos: Rapid7 (SOC 2 II + ISO 27001 — InsightIDR via ControlCase); (4) Vendors críticos sin PCI directo: GitHub (SOC 2 II + ISO 27001), Bitwarden (SOC 2 II); (5) Open source vetted via SDLC: Wazuh, GoPhish, Kong; (6) Servicios profesionales: HR Empresa Colombia SAS (background checks Q89); (7) TPSP NUEVO H1 2026: Rapid7 InsightIDR via ControlCase (onboarded 2026-04-10). Para cada vendor: TMPL-014 record en pci_compliance.vendor_tracker table. §5 sample agreement clauses (DO MSA §4.2/4.3, ControlCase MSA §3.1/3.2), §6 monitoring + audit cadence anual, §7 vendor exit en POL-008 §7.


1. Mapeo PCI DSS v4.0 ​

RequisitoDescripciónSección
12.8.1Mantain list of TPSPs§2 inventario 11 vendors
12.8.2Written agreements with TPSPs§3 MSAs + §5 sample clauses
12.8.3Process for engaging TPSPs (due diligence)POL-008 §3 + TMPL-014 workflow
12.8.4Monitor TPSP compliance status annually§4 compliance attestations + §6 audit cadence
12.8.5Information on shared responsibilities§4 per-vendor SRM matrix

2. Inventario completo — 11 vendors activos ​

Q91-T1

2.1 Tabla maestra (TMPL-014 records) ​

#VendorServiceRiskStatus
1DigitalOcean, LLCCloud infra (DOKS, DBaaS, Spaces, Cloud Firewall)CriticalActive ✓
2ControlCase ComplianceQSA + ASV + IDR + PCIUA SaaSCriticalActive ✓
3Rapid7, Inc. (via ControlCase)InsightIDR central syslog SIEMCriticalActive ✓ (since 2026-04-10)
4CredibancoAcquirer + payment processor ColombiaCriticalActive ✓
5GitHub, Inc.Source code + CI/CD (Actions)HighActive ✓
6Bitwarden, Inc.Credential vault CTOHighActive ✓
7Wazuh, Inc.SIEM stack (open source — community + commercial)MediumActive ✓
8GoPhishOpen source phishing sim (self-hosted)LowActive ✓
9Kong Inc.Open source API gateway (self-hosted)LowActive ✓
10HR Empresa Colombia SASBackground check servicesMediumActive ✓
11Coalfire (DO's QSA — indirect)PCI attestation for DOLowIndirect (no direct contract)

2.2 Vendor exclusions (out of scope) ​

Vendors no en alcance para este Q91 porque no acceden al CDE ni soportan la entrega del servicio:

VendorRazón
Google (Gmail)Email del CTO solamente
Stripe (test PANs only)Solo para tests de tokenización; no procesamiento real
WhatsApp BusinessCliente comm, no CDE
Personal bankingNo relacionado con la operación de Fintrixs

3. Vendor critical — DigitalOcean (sample completo) ​

Q91-T2

3.1 TMPL-014 record DigitalOcean ​

Vendor ID:                  VND-2024-001
Legal name:                 DigitalOcean, LLC
Commercial name:            DigitalOcean
Vendor type:                IaaS / SaaS
Country of incorporation:   USA (NYSE: DOCN)
Primary PoC:                Account Management Team
Security PoC:               [email protected]
Account manager:            (Enterprise tier)

─── SERVICES ───────────────────────────────────
Service category:           Cloud infra
Service description:        Kubernetes (DOKS) + Managed PostgreSQL + Droplets +
                            Spaces (S3) + Cloud Firewall + VPC
Data accessed:              CHD (within DOKS apps + DBaaS prod)
Systems accessed:           Direct CDE (entire infra)
Network access path:        DO maintains infra; CTO accesses via API/console

─── CONTRACTUAL ────────────────────────────────
MSA effective date:         2024-08-15
MSA expiration date:        Auto-renew annually
MSA renewal type:           Auto-renew
DPA in place:               Yes (Data Processing Agreement)
DPA last updated:           2025-09-10 (GDPR + CCPA addendum)
SLA tier:                   Production (99.99% on critical services)
SLA uptime:                 99.99% DBaaS, 99.9% Droplets
Liability cap:              12 months fees (per MSA §8)
Termination notice:         60 days
Audit rights clause:        Yes (MSA §4.3) — via SOC 2/SOC 3/CSA Self-Assessment request

─── COMPLIANCE (verificado visualmente 2026-06-16) ────────
Trust Center URL:           https://www.digitalocean.com/trust/certification-reports

PCI DSS Level 1 SP AOC:     ❌ NO — DO no es PCI Level 1 Service Provider
PCI-DSS SAQ-A:               ✓ Yes — Zero-Footprint data policy
                              "DO commits to NOT storing, processing, or
                               transmitting cardholder data within our
                               administrative environment"
                              (texto literal del Trust Center)

SOC 2 Type II:               ✓ Yes — issued by Schellman & Company
SOC 3 Type II:               ✓ Yes — issued by Schellman & Company
SOC 2 download:              https://cloud.digitalocean.com/trust/security-reports
CIS Benchmarks:              ✓ Yes — CIS Foundations + CIS Services
Global PRP Certification:    ✓ Yes — certified by Schellman
CSA STAR Level 1:            ✓ Yes (Self-Assessment, not 3rd-party attested)
                              16 cloud-specific domains
GDPR + DPA:                  ✓ Executed (https://www.digitalocean.com/legal/data-processing-agreement)
HIPAA eligibility:           ✓ Yes (eligibility — no BAA universal)
DORA eligibility:            ✓ Yes
ISO 27001:                   NOT listed in DO Trust Center
ISO 27017 / 27018:           NOT listed
FedRAMP:                     NOT listed

─── ACK ────────────────────────────────────────
Vendor compliance ack:      MSA §4.2 — commitment a security program SOC 2 II
Reference clause:           MSA §4.2 (Security) + §4.3 (Audits) + DPA executed
Last ack date:              2024-08-15 (MSA signature) + DPA renewal 2025-09-10
Re-attestation due:         Annual (auto-renewal)
PCI delegation basis:       SOC 2 II by Schellman + CSA Self-Assessment + DPA
                            (DO no es PCI Level 1 SP — solo SAQ-A zero-footprint)
                            Práctica aceptada por PCI SSC para cloud providers
                            que no son Level 1 SP.

IMPORTANT NOTE:              DO PCI-DSS SAQ-A NO se puede invocar para heredar
                            controles PCI de CHD. SAQ-A solo certifica que DO
                            no toca CHD en su env administrativo. Para Fintrixs,
                            esto significa que SOMOS 100% responsables PCI por
                            todos los workloads en DOKS, DBaaS, Spaces.

─── RISK ──────────────────────────────────────
Risk score:                  Critical
Risk justification:          Entire infra hosting CDE; single-cloud risk; multi-tenant SaaS
Annual review date:          2026-08-15
Last incident with vendor:   None

3.2 Shared responsibility matrix con DigitalOcean ​

PCI ReqResponsabilityNotes
1.x Network firewallsSharedDO = perimeter Cloud Firewalls; Fintrixs = K8s NetworkPolicies + intra-VPC config
2.x ConfigurationsSharedDO = hypervisor + DBaaS managed; Fintrixs = K8s configs + app configs
3.x CHD storageFintrixsDBaaS at-rest encryption (DO); design + key mgmt (Fintrixs)
4.x Encryption transitSharedDO provides VPC private network; Fintrixs uses TLS 1.2+
5.x Anti-malwareFintrixsDOKS nodes per Fintrixs config (Falco + Wazuh)
6.x SDLCFintrixsAll code + deployment by Fintrixs
7.x Access controlSharedDO console = DO MFA; K8s/DBaaS RBAC = Fintrixs
8.x AuthenticationSharedDO account = DO MFA; service accounts = Fintrixs
9.x PhysicalDigitalOceanDC physical security (Q60)
10.x LoggingSharedDBaaS logs (DO); app logs (Fintrixs); SIEM (Fintrixs)
11.x TestingSharedDO does their own pentest; Fintrixs does theirs for app layer
12.x Security policyFintrixsAll policies by Fintrixs

3.3 Sample MSA clauses (DigitalOcean) ​

DigitalOcean MSA v2025-03-15 — Cláusulas relevantes:

§ 4.2 (Security)
"DigitalOcean shall maintain a comprehensive information security program
designed to protect Customer Data and to comply with applicable laws,
including PHYSICAL, ADMINISTRATIVE, and TECHNICAL safeguards consistent
with industry standards."

§ 4.3 (Audits)
"DigitalOcean shall provide Customer with copies of its CURRENT
attestation reports (SOC 2 Type II, SOC 3, CSA STAR) upon written request,
subject to applicable confidentiality terms (NDA)."

(Note: DigitalOcean is NOT a PCI DSS Level 1 Service Provider. They have
PCI-DSS SAQ-A (Zero-Footprint) which only certifies that DO does not handle
CHD in their own administrative environment. Compliance verification for
Fintrixs use is via SOC 2 Type II by Schellman & Company + CSA Self-Assessment
Level 1 + DPA. Verified visually at Trust Center 2026-06-16.)

§ 4.5 (Data Processing Addendum)
"Customer may execute the DPA to govern processing of Personal Data, in
accordance with GDPR (EU 2016/679) and CCPA (Cal. Civ. Code §1798.100)."

§ 8 (Limitation of Liability)
"Liability cap: amounts paid in the twelve (12) months prior to the
incident."

§ 11 (Termination)
"Either party may terminate this Agreement upon 60 days' written notice."

4. Compliance attestations summary ​

Q91-T3

4.1 Tabla consolidada ​

#VendorPCI DSSSOC 2 IIISO 27001ISO 27017ISO 27018Trust Center
1DigitalOcean⚠ SAQ-A only (NOT Level 1 SP)✓ Schellman✓ Self-Assess——digitalocean.com/trust
2ControlCaseLevel 1 SP ✓✓ (2025)✓——controlcase.com/trust
3Rapid7— (via ControlCase)✓ (2025)✓——trust.rapid7.com
4CredibancoLevel 1 SP ✓ + Visa/MC✓✓——credibanco.com
5GitHub— (no CHD)✓ (2025)✓——trust.github.com
6Bitwarden— (no CHD)✓ (2025)✓——bitwarden.com/security
7Wazuh—— (open source)———wazuh.com (vetted via Q37)
8GoPhish—— (open source)———(vetted via Q37)
9Kong— (self-hosted)— (open source)———(vetted via Q37)
10HR Empresa Colombia——ISO 27001 ✓——(CRA registered Colombia)
11Coalfire(assistor general)✓✓——coalfire.com

4.2 Status code summary ​

Vendor críticoBase de delegación PCIAttestation valid untilNext renewal
DigitalOceanSOC 2 II by Schellman + CSA Self-Assessment + DPA (NO Level 1 SP — solo SAQ-A)SOC 2 2026-Q42026-12
ControlCasePCI DSS Level 1 SP AOC2026-Q32026-09
CredibancoPCI DSS Level 1 + Visa/MC2026-Q42026-11

Coverage: 11/11 vendors con attestation o documentación vigente. Importante: 2 vendors con PCI DSS Level 1 SP AOC dedicado: ControlCase + Credibanco. DigitalOcean tiene PCI-DSS SAQ-A (Zero-Footprint — solo cubre su env administrativo, no CHD handling para clientes). La delegación de PCI 9.x + 11.2 a DO se basa en SOC 2 Type II by Schellman & Company + CSA Self-Assessment Level 1 + DPA. Práctica aceptada por PCI SSC para cloud providers que no son Level 1 SP. Implicación crítica: Fintrixs es 100% responsable PCI por workloads en DOKS, DBaaS y Spaces — DO solo provee infraestructura, no servicio PCI.


5. Sample agreement clauses extraídas ​

Q91-T4

5.1 ControlCase MSA — Security Clauses ​

ControlCase Master Services Agreement v2024-01-01

§ 3.1 (Confidentiality)
"ControlCase shall protect Customer Data with at least the same degree of
care as it uses to protect its own confidential information, but not less
than a reasonable standard of care."

§ 3.2 (PCI Compliance Specific)
"ControlCase confirms its PCI DSS Level 1 Service Provider status for the
services provided under this Agreement (QSA + ASV + InsightIDR managed +
PCIUA awareness training). Annual attestation reports shall be provided
to Customer."

§ 4.1 (Data Processing Agreement)
"For Personal Data processed on behalf of Customer, ControlCase shall act
as Data Processor per GDPR Article 28."

§ 5 (Security Incidents)
"ControlCase shall notify Customer of any Security Incident affecting
Customer Data within 24 hours of discovery, providing reasonable details."

§ 7 (Audit Rights)
"Customer may request a copy of the SOC 2 Type II report annually."

5.2 GitHub Enterprise Terms — Relevant Clauses ​

GitHub Enterprise Cloud — Customer Terms (relevante para Fintrixs)

§ 4.3 (Security Standards)
"GitHub shall maintain security controls consistent with SOC 2 Type II
attestation. Customer may request the most recent SOC 2 report under NDA."

§ 4.4 (Customer Data)
"Customer Data is owned by Customer. GitHub does not use Customer Data
for training AI models without explicit consent."

§ 6.2 (Subprocessors)
"GitHub uses subprocessors (Microsoft Azure for infrastructure) and
maintains an up-to-date list at https://github.com/site/dpa."

5.3 Bitwarden Business Terms ​

Bitwarden Business Subscription Agreement v2024

§ 5 (Security)
"Bitwarden maintains zero-knowledge architecture: customer master passwords
and encryption keys are never stored on Bitwarden servers."

§ 6 (Attestations)
"Annual SOC 2 Type II audit conducted by an independent firm.
Report available under NDA via [email protected]."

6. Annual monitoring + audit cadence ​

Q91-T5

6.1 Annual review calendar 2026 ​

MonthVendorAction
AprCredibancoAnnual MSA review + PCI status check
Jun(this cycle)TMPL-014 templates emitted + tracker populated
AugDigitalOceanAnnual MSA + SOC 2 II Schellman + SAQ-A + CSA Self-Assess + DPA refresh
SepControlCaseAnnual review + SOC 2 II report request
OctGitHubAnnual review + SOC 2 II report
NovWazuh + GoPhish + KongOSS dependency audit (Q37 SDLC)
DecBitwarden + Rapid7Annual review + SOC 2 II

6.2 Trigger automation ​

TriggerAction
pci_valid_until <= NOW() + 60 daysEmail reminder CISO + procurement
soc2_last_report > NOW() - 14 monthsRequest new SOC 2 report
msa_expiration_date <= NOW() + 90 daysInitiate renewal
New vendor proposedPOL-008 §3 due diligence triggered
Vendor security incident reportedPOL-007 §5 + vendor escalation

7. Vendor exit + decommission ​

Q91-T6

7.1 Exit triggers ​

TriggerAction
Vendor PCI attestation expira sin renewalSuspend access + accelerated migration
Vendor security incident severity CriticalActivate IRP (POL-007 §5) + risk assessment
Vendor M&A → new entityRe-evaluate due diligence + new MSA
Service no longer neededStandard decommission

7.2 Decommission checklist (POL-008 §7) ​

Day 0:    Notice of termination sent
Day 7:    Access list audit + revocation plan
Day 14:   Access revoked (API tokens, accounts, IPs allowlisted)
Day 30:   Data export + verification
Day 60:   Data deletion confirmation + certificate of destruction
Day 90:   Final MSA closure + archive records (7 años retention)

7.3 Historical decommissions (none in H1 2026) ​

No vendor offboarded en H1 2026. All 11 vendors permanecen activos.


8. Vendor risk dashboard ​

Q91-T7

8.1 Risk distribution ​

Risk scoreCountVendors
Critical4DigitalOcean, ControlCase, Rapid7, Credibanco
High2GitHub, Bitwarden
Medium2Wazuh, HR Empresa Colombia
Low3GoPhish, Kong, Coalfire (indirect)

8.2 Hot list — vendors a monitorear ​

VendorReason
Rapid7 (NEW 2026-04-10)Recently onboarded — needs 6-month check
CredibancoAnnual renewal Q4 2026
DigitalOceanSingle-cloud concentration risk

9. Cómo el QSA verifica cada entregable ​

Solicitado por QSADónde se prueba
Acuerdo de servicios vigente (seguridad/disponibilidad/conf/integridad)§3 DO + §5 ControlCase + GitHub + Bitwarden sample clauses
Estado de cumplimiento (normativas/estándares)§4 11/11 vendors attestation table
Lista de requisitos seguridad cada vendor maneja§3.2 DO shared responsibility matrix (sample); other vendors in tracker §2
Acuerdos§3.3 + §5 (textual MSA quotes)

10. Vínculo con otros controles ​

Documentación Confidencial — Solo para uso interno y auditoría PCI DSS