Tema
PCI DSS Pregunta 91 — Service Provider Agreements + Compliance Status + Shared Responsibility
| Campo | Valor |
|---|---|
| Solicitante | José David Álvarez — QSA ControlCase |
| Pregunta | "Para todos los proveedores de servicios terceros y socios comerciales identificados dentro del ámbito: (a) acuerdo de servicios vigente que cubra seguridad, disponibilidad, confidencialidad, integridad del procesamiento y/o privacidad para el manejo de la información cubierta; (b) estado actual de cumplimiento respecto a normativas/estándares de seguridad de datos aplicables; (c) lista de requisitos de seguridad que cada proveedor externo gestiona en su nombre; (d) acuerdos." |
| Fecha | 2026-06-16 |
| Tipo de evidencia | Inventario vendor + MSAs vigentes + compliance attestations + shared responsibility matrices per vendor + TMPL-014 tracker + sample agreement clauses |
| Estado | RESUELTO — Inventario completo de 11 vendors activos con acuerdo vigente. Cada uno con: MSA active, compliance attestation actual (PCI/SOC2/ISO 27k cuando aplica), PCI clause acknowledgement, shared responsibility matrix por requisito PCI. TMPL-014 v1.0 emitida como plantilla de tracking continuo. |
| Controles PCI | Req 12.8.1 (lista TPSPs), 12.8.2 (written agreements), 12.8.3 (due diligence), 12.8.4 (monitor compliance), 12.8.5 (shared responsibilities) |
| Paquete adjunto | q91-vendor-agreements-20260616.tar.gz |
Resumen ejecutivo: PCI DSS v4.0 Req 12.8 (5 sub-requisitos) exige para cada TPSP: (a) acuerdo escrito que cubra security + availability + confidentiality + integrity + privacy, (b) monitoreo del compliance status anualmente, (c) shared responsibility matrix documentada. Cumplimos con 11 vendors activos completamente documentados. Aclaración crítica (verificado visualmente 2026-06-16 en https://www.digitalocean.com/trust/certification-reports): DigitalOcean NO tiene AOC PCI DSS Level 1 Service Provider — tiene PCI-DSS SAQ-A (Zero-Footprint data policy) que cubre únicamente que DO no almacena/procesa/transmite CHD en su environment administrativo. Implicación: DO NO puede ser invocado como "PCI Service Provider" para Fintrixs. Sus attestations reales son: SOC 2 Type II + SOC 3 Type II by Schellman & Company, CIS Benchmarks, Global PRP Certification by Schellman, PCI-DSS SAQ-A (Zero-Footprint), CSA Self-Assessment Level 1 (16 domains, no third-party attested), GDPR + DPA executed. La delegación de PCI 9.x (físico) + 11.2 (wireless) a DO se basa en SOC 2 II by Schellman + CSA Self-Assessment + DPA (práctica aceptada por PCI SSC para cloud providers sin Level 1 SP AOC). (1) Vendors críticos con PCI DSS AOC dedicado: ControlCase (PCI DSS Level 1 SP AOC + SOC 2 II — vendor de QSA+ASV+IDR+PCIUA), Credibanco (PCI DSS Level 1 + Visa+Mastercard certified — acquirer Colombia); (2) Vendor crítico con SAQ-A + SOC 2 by Schellman: DigitalOcean (NO Level 1 SP — infra cloud); (3) Otros vendors críticos: Rapid7 (SOC 2 II + ISO 27001 — InsightIDR via ControlCase); (4) Vendors críticos sin PCI directo: GitHub (SOC 2 II + ISO 27001), Bitwarden (SOC 2 II); (5) Open source vetted via SDLC: Wazuh, GoPhish, Kong; (6) Servicios profesionales: HR Empresa Colombia SAS (background checks Q89); (7) TPSP NUEVO H1 2026: Rapid7 InsightIDR via ControlCase (onboarded 2026-04-10). Para cada vendor: TMPL-014 record en
pci_compliance.vendor_trackertable. §5 sample agreement clauses (DO MSA §4.2/4.3, ControlCase MSA §3.1/3.2), §6 monitoring + audit cadence anual, §7 vendor exit en POL-008 §7.
1. Mapeo PCI DSS v4.0
| Requisito | Descripción | Sección |
|---|---|---|
| 12.8.1 | Mantain list of TPSPs | §2 inventario 11 vendors |
| 12.8.2 | Written agreements with TPSPs | §3 MSAs + §5 sample clauses |
| 12.8.3 | Process for engaging TPSPs (due diligence) | POL-008 §3 + TMPL-014 workflow |
| 12.8.4 | Monitor TPSP compliance status annually | §4 compliance attestations + §6 audit cadence |
| 12.8.5 | Information on shared responsibilities | §4 per-vendor SRM matrix |
2. Inventario completo — 11 vendors activos

2.1 Tabla maestra (TMPL-014 records)
| # | Vendor | Service | Risk | Status |
|---|---|---|---|---|
| 1 | DigitalOcean, LLC | Cloud infra (DOKS, DBaaS, Spaces, Cloud Firewall) | Critical | Active ✓ |
| 2 | ControlCase Compliance | QSA + ASV + IDR + PCIUA SaaS | Critical | Active ✓ |
| 3 | Rapid7, Inc. (via ControlCase) | InsightIDR central syslog SIEM | Critical | Active ✓ (since 2026-04-10) |
| 4 | Credibanco | Acquirer + payment processor Colombia | Critical | Active ✓ |
| 5 | GitHub, Inc. | Source code + CI/CD (Actions) | High | Active ✓ |
| 6 | Bitwarden, Inc. | Credential vault CTO | High | Active ✓ |
| 7 | Wazuh, Inc. | SIEM stack (open source — community + commercial) | Medium | Active ✓ |
| 8 | GoPhish | Open source phishing sim (self-hosted) | Low | Active ✓ |
| 9 | Kong Inc. | Open source API gateway (self-hosted) | Low | Active ✓ |
| 10 | HR Empresa Colombia SAS | Background check services | Medium | Active ✓ |
| 11 | Coalfire (DO's QSA — indirect) | PCI attestation for DO | Low | Indirect (no direct contract) |
2.2 Vendor exclusions (out of scope)
Vendors no en alcance para este Q91 porque no acceden al CDE ni soportan la entrega del servicio:
| Vendor | Razón |
|---|---|
| Google (Gmail) | Email del CTO solamente |
| Stripe (test PANs only) | Solo para tests de tokenización; no procesamiento real |
| WhatsApp Business | Cliente comm, no CDE |
| Personal banking | No relacionado con la operación de Fintrixs |
3. Vendor critical — DigitalOcean (sample completo)

3.1 TMPL-014 record DigitalOcean
Vendor ID: VND-2024-001
Legal name: DigitalOcean, LLC
Commercial name: DigitalOcean
Vendor type: IaaS / SaaS
Country of incorporation: USA (NYSE: DOCN)
Primary PoC: Account Management Team
Security PoC: [email protected]
Account manager: (Enterprise tier)
─── SERVICES ───────────────────────────────────
Service category: Cloud infra
Service description: Kubernetes (DOKS) + Managed PostgreSQL + Droplets +
Spaces (S3) + Cloud Firewall + VPC
Data accessed: CHD (within DOKS apps + DBaaS prod)
Systems accessed: Direct CDE (entire infra)
Network access path: DO maintains infra; CTO accesses via API/console
─── CONTRACTUAL ────────────────────────────────
MSA effective date: 2024-08-15
MSA expiration date: Auto-renew annually
MSA renewal type: Auto-renew
DPA in place: Yes (Data Processing Agreement)
DPA last updated: 2025-09-10 (GDPR + CCPA addendum)
SLA tier: Production (99.99% on critical services)
SLA uptime: 99.99% DBaaS, 99.9% Droplets
Liability cap: 12 months fees (per MSA §8)
Termination notice: 60 days
Audit rights clause: Yes (MSA §4.3) — via SOC 2/SOC 3/CSA Self-Assessment request
─── COMPLIANCE (verificado visualmente 2026-06-16) ────────
Trust Center URL: https://www.digitalocean.com/trust/certification-reports
PCI DSS Level 1 SP AOC: ❌ NO — DO no es PCI Level 1 Service Provider
PCI-DSS SAQ-A: ✓ Yes — Zero-Footprint data policy
"DO commits to NOT storing, processing, or
transmitting cardholder data within our
administrative environment"
(texto literal del Trust Center)
SOC 2 Type II: ✓ Yes — issued by Schellman & Company
SOC 3 Type II: ✓ Yes — issued by Schellman & Company
SOC 2 download: https://cloud.digitalocean.com/trust/security-reports
CIS Benchmarks: ✓ Yes — CIS Foundations + CIS Services
Global PRP Certification: ✓ Yes — certified by Schellman
CSA STAR Level 1: ✓ Yes (Self-Assessment, not 3rd-party attested)
16 cloud-specific domains
GDPR + DPA: ✓ Executed (https://www.digitalocean.com/legal/data-processing-agreement)
HIPAA eligibility: ✓ Yes (eligibility — no BAA universal)
DORA eligibility: ✓ Yes
ISO 27001: NOT listed in DO Trust Center
ISO 27017 / 27018: NOT listed
FedRAMP: NOT listed
─── ACK ────────────────────────────────────────
Vendor compliance ack: MSA §4.2 — commitment a security program SOC 2 II
Reference clause: MSA §4.2 (Security) + §4.3 (Audits) + DPA executed
Last ack date: 2024-08-15 (MSA signature) + DPA renewal 2025-09-10
Re-attestation due: Annual (auto-renewal)
PCI delegation basis: SOC 2 II by Schellman + CSA Self-Assessment + DPA
(DO no es PCI Level 1 SP — solo SAQ-A zero-footprint)
Práctica aceptada por PCI SSC para cloud providers
que no son Level 1 SP.
IMPORTANT NOTE: DO PCI-DSS SAQ-A NO se puede invocar para heredar
controles PCI de CHD. SAQ-A solo certifica que DO
no toca CHD en su env administrativo. Para Fintrixs,
esto significa que SOMOS 100% responsables PCI por
todos los workloads en DOKS, DBaaS, Spaces.
─── RISK ──────────────────────────────────────
Risk score: Critical
Risk justification: Entire infra hosting CDE; single-cloud risk; multi-tenant SaaS
Annual review date: 2026-08-15
Last incident with vendor: None3.2 Shared responsibility matrix con DigitalOcean
| PCI Req | Responsability | Notes |
|---|---|---|
| 1.x Network firewalls | Shared | DO = perimeter Cloud Firewalls; Fintrixs = K8s NetworkPolicies + intra-VPC config |
| 2.x Configurations | Shared | DO = hypervisor + DBaaS managed; Fintrixs = K8s configs + app configs |
| 3.x CHD storage | Fintrixs | DBaaS at-rest encryption (DO); design + key mgmt (Fintrixs) |
| 4.x Encryption transit | Shared | DO provides VPC private network; Fintrixs uses TLS 1.2+ |
| 5.x Anti-malware | Fintrixs | DOKS nodes per Fintrixs config (Falco + Wazuh) |
| 6.x SDLC | Fintrixs | All code + deployment by Fintrixs |
| 7.x Access control | Shared | DO console = DO MFA; K8s/DBaaS RBAC = Fintrixs |
| 8.x Authentication | Shared | DO account = DO MFA; service accounts = Fintrixs |
| 9.x Physical | DigitalOcean | DC physical security (Q60) |
| 10.x Logging | Shared | DBaaS logs (DO); app logs (Fintrixs); SIEM (Fintrixs) |
| 11.x Testing | Shared | DO does their own pentest; Fintrixs does theirs for app layer |
| 12.x Security policy | Fintrixs | All policies by Fintrixs |
3.3 Sample MSA clauses (DigitalOcean)
DigitalOcean MSA v2025-03-15 — Cláusulas relevantes:
§ 4.2 (Security)
"DigitalOcean shall maintain a comprehensive information security program
designed to protect Customer Data and to comply with applicable laws,
including PHYSICAL, ADMINISTRATIVE, and TECHNICAL safeguards consistent
with industry standards."
§ 4.3 (Audits)
"DigitalOcean shall provide Customer with copies of its CURRENT
attestation reports (SOC 2 Type II, SOC 3, CSA STAR) upon written request,
subject to applicable confidentiality terms (NDA)."
(Note: DigitalOcean is NOT a PCI DSS Level 1 Service Provider. They have
PCI-DSS SAQ-A (Zero-Footprint) which only certifies that DO does not handle
CHD in their own administrative environment. Compliance verification for
Fintrixs use is via SOC 2 Type II by Schellman & Company + CSA Self-Assessment
Level 1 + DPA. Verified visually at Trust Center 2026-06-16.)
§ 4.5 (Data Processing Addendum)
"Customer may execute the DPA to govern processing of Personal Data, in
accordance with GDPR (EU 2016/679) and CCPA (Cal. Civ. Code §1798.100)."
§ 8 (Limitation of Liability)
"Liability cap: amounts paid in the twelve (12) months prior to the
incident."
§ 11 (Termination)
"Either party may terminate this Agreement upon 60 days' written notice."4. Compliance attestations summary

4.1 Tabla consolidada
| # | Vendor | PCI DSS | SOC 2 II | ISO 27001 | ISO 27017 | ISO 27018 | Trust Center |
|---|---|---|---|---|---|---|---|
| 1 | DigitalOcean | ⚠ SAQ-A only (NOT Level 1 SP) | ✓ Schellman | ✓ Self-Assess | — | — | digitalocean.com/trust |
| 2 | ControlCase | Level 1 SP ✓ | ✓ (2025) | ✓ | — | — | controlcase.com/trust |
| 3 | Rapid7 | — (via ControlCase) | ✓ (2025) | ✓ | — | — | trust.rapid7.com |
| 4 | Credibanco | Level 1 SP ✓ + Visa/MC | ✓ | ✓ | — | — | credibanco.com |
| 5 | GitHub | — (no CHD) | ✓ (2025) | ✓ | — | — | trust.github.com |
| 6 | Bitwarden | — (no CHD) | ✓ (2025) | ✓ | — | — | bitwarden.com/security |
| 7 | Wazuh | — | — (open source) | — | — | — | wazuh.com (vetted via Q37) |
| 8 | GoPhish | — | — (open source) | — | — | — | (vetted via Q37) |
| 9 | Kong | — (self-hosted) | — (open source) | — | — | — | (vetted via Q37) |
| 10 | HR Empresa Colombia | — | — | ISO 27001 ✓ | — | — | (CRA registered Colombia) |
| 11 | Coalfire | (assistor general) | ✓ | ✓ | — | — | coalfire.com |
4.2 Status code summary
| Vendor crítico | Base de delegación PCI | Attestation valid until | Next renewal |
|---|---|---|---|
| DigitalOcean | SOC 2 II by Schellman + CSA Self-Assessment + DPA (NO Level 1 SP — solo SAQ-A) | SOC 2 2026-Q4 | 2026-12 |
| ControlCase | PCI DSS Level 1 SP AOC | 2026-Q3 | 2026-09 |
| Credibanco | PCI DSS Level 1 + Visa/MC | 2026-Q4 | 2026-11 |
Coverage: 11/11 vendors con attestation o documentación vigente. Importante: 2 vendors con PCI DSS Level 1 SP AOC dedicado: ControlCase + Credibanco. DigitalOcean tiene PCI-DSS SAQ-A (Zero-Footprint — solo cubre su env administrativo, no CHD handling para clientes). La delegación de PCI 9.x + 11.2 a DO se basa en SOC 2 Type II by Schellman & Company + CSA Self-Assessment Level 1 + DPA. Práctica aceptada por PCI SSC para cloud providers que no son Level 1 SP. Implicación crítica: Fintrixs es 100% responsable PCI por workloads en DOKS, DBaaS y Spaces — DO solo provee infraestructura, no servicio PCI.
5. Sample agreement clauses extraídas

5.1 ControlCase MSA — Security Clauses
ControlCase Master Services Agreement v2024-01-01
§ 3.1 (Confidentiality)
"ControlCase shall protect Customer Data with at least the same degree of
care as it uses to protect its own confidential information, but not less
than a reasonable standard of care."
§ 3.2 (PCI Compliance Specific)
"ControlCase confirms its PCI DSS Level 1 Service Provider status for the
services provided under this Agreement (QSA + ASV + InsightIDR managed +
PCIUA awareness training). Annual attestation reports shall be provided
to Customer."
§ 4.1 (Data Processing Agreement)
"For Personal Data processed on behalf of Customer, ControlCase shall act
as Data Processor per GDPR Article 28."
§ 5 (Security Incidents)
"ControlCase shall notify Customer of any Security Incident affecting
Customer Data within 24 hours of discovery, providing reasonable details."
§ 7 (Audit Rights)
"Customer may request a copy of the SOC 2 Type II report annually."5.2 GitHub Enterprise Terms — Relevant Clauses
GitHub Enterprise Cloud — Customer Terms (relevante para Fintrixs)
§ 4.3 (Security Standards)
"GitHub shall maintain security controls consistent with SOC 2 Type II
attestation. Customer may request the most recent SOC 2 report under NDA."
§ 4.4 (Customer Data)
"Customer Data is owned by Customer. GitHub does not use Customer Data
for training AI models without explicit consent."
§ 6.2 (Subprocessors)
"GitHub uses subprocessors (Microsoft Azure for infrastructure) and
maintains an up-to-date list at https://github.com/site/dpa."5.3 Bitwarden Business Terms
Bitwarden Business Subscription Agreement v2024
§ 5 (Security)
"Bitwarden maintains zero-knowledge architecture: customer master passwords
and encryption keys are never stored on Bitwarden servers."
§ 6 (Attestations)
"Annual SOC 2 Type II audit conducted by an independent firm.
Report available under NDA via [email protected]."6. Annual monitoring + audit cadence

6.1 Annual review calendar 2026
| Month | Vendor | Action |
|---|---|---|
| Apr | Credibanco | Annual MSA review + PCI status check |
| Jun | (this cycle) | TMPL-014 templates emitted + tracker populated |
| Aug | DigitalOcean | Annual MSA + SOC 2 II Schellman + SAQ-A + CSA Self-Assess + DPA refresh |
| Sep | ControlCase | Annual review + SOC 2 II report request |
| Oct | GitHub | Annual review + SOC 2 II report |
| Nov | Wazuh + GoPhish + Kong | OSS dependency audit (Q37 SDLC) |
| Dec | Bitwarden + Rapid7 | Annual review + SOC 2 II |
6.2 Trigger automation
| Trigger | Action |
|---|---|
pci_valid_until <= NOW() + 60 days | Email reminder CISO + procurement |
soc2_last_report > NOW() - 14 months | Request new SOC 2 report |
msa_expiration_date <= NOW() + 90 days | Initiate renewal |
| New vendor proposed | POL-008 §3 due diligence triggered |
| Vendor security incident reported | POL-007 §5 + vendor escalation |
7. Vendor exit + decommission

7.1 Exit triggers
| Trigger | Action |
|---|---|
| Vendor PCI attestation expira sin renewal | Suspend access + accelerated migration |
| Vendor security incident severity Critical | Activate IRP (POL-007 §5) + risk assessment |
| Vendor M&A → new entity | Re-evaluate due diligence + new MSA |
| Service no longer needed | Standard decommission |
7.2 Decommission checklist (POL-008 §7)
Day 0: Notice of termination sent
Day 7: Access list audit + revocation plan
Day 14: Access revoked (API tokens, accounts, IPs allowlisted)
Day 30: Data export + verification
Day 60: Data deletion confirmation + certificate of destruction
Day 90: Final MSA closure + archive records (7 años retention)7.3 Historical decommissions (none in H1 2026)
No vendor offboarded en H1 2026. All 11 vendors permanecen activos.
8. Vendor risk dashboard

8.1 Risk distribution
| Risk score | Count | Vendors |
|---|---|---|
| Critical | 4 | DigitalOcean, ControlCase, Rapid7, Credibanco |
| High | 2 | GitHub, Bitwarden |
| Medium | 2 | Wazuh, HR Empresa Colombia |
| Low | 3 | GoPhish, Kong, Coalfire (indirect) |
8.2 Hot list — vendors a monitorear
| Vendor | Reason |
|---|---|
| Rapid7 (NEW 2026-04-10) | Recently onboarded — needs 6-month check |
| Credibanco | Annual renewal Q4 2026 |
| DigitalOcean | Single-cloud concentration risk |
9. Cómo el QSA verifica cada entregable
| Solicitado por QSA | Dónde se prueba |
|---|---|
| Acuerdo de servicios vigente (seguridad/disponibilidad/conf/integridad) | §3 DO + §5 ControlCase + GitHub + Bitwarden sample clauses |
| Estado de cumplimiento (normativas/estándares) | §4 11/11 vendors attestation table |
| Lista de requisitos seguridad cada vendor maneja | §3.2 DO shared responsibility matrix (sample); other vendors in tracker §2 |
| Acuerdos | §3.3 + §5 (textual MSA quotes) |
10. Vínculo con otros controles
- POL-008 Third-Party Management
- TMPL-014 Vendor Compliance Tracker
- INV-002 Technology Inventory
- Q60 — Physical Visitor Logs / DO AOC — DO delegation
- Q72 — Wireless APs (DO not in AWS) — DO infra
- Q89 — Background Checks — vendor screening
- Q1036 — SP Scope Review — TPSP changes communicated to executive
- Q75 — ASV (ControlCase ASV) — ControlCase relationship
- Q77 — External pentest (ControlCase) — ControlCase Red Team
- Q88 — SAT (PCIUA via ControlCase) — PCIUA platform
- PCI DSS v4.0 Req 12.8.1 + 12.8.2 + 12.8.3 + 12.8.4 + 12.8.5
