Skip to content

PCI DSS Pregunta 91 — Service Provider Agreements + Compliance Status + Shared Responsibility

CampoValor
SolicitanteJosé David Álvarez — QSA ControlCase
Pregunta"Para todos los proveedores de servicios terceros y socios comerciales identificados dentro del ámbito: (a) acuerdo de servicios vigente que cubra seguridad, disponibilidad, confidencialidad, integridad del procesamiento y/o privacidad para el manejo de la información cubierta; (b) estado actual de cumplimiento respecto a normativas/estándares de seguridad de datos aplicables; (c) lista de requisitos de seguridad que cada proveedor externo gestiona en su nombre; (d) acuerdos."
Fecha2026-06-16
Tipo de evidenciaInventario vendor + MSAs vigentes + compliance attestations + shared responsibility matrices per vendor + TMPL-014 tracker + sample agreement clauses
EstadoRESUELTO — Inventario completo de 11 vendors activos con acuerdo vigente. Cada uno con: MSA active, compliance attestation actual (PCI/SOC2/ISO 27k cuando aplica), PCI clause acknowledgement, shared responsibility matrix por requisito PCI. TMPL-014 v1.0 emitida como plantilla de tracking continuo.
Controles PCIReq 12.8.1 (lista TPSPs), 12.8.2 (written agreements), 12.8.3 (due diligence), 12.8.4 (monitor compliance), 12.8.5 (shared responsibilities)
Paquete adjuntoq91-vendor-agreements-20260616.tar.gz

Resumen ejecutivo: PCI DSS v4.0 Req 12.8 (5 sub-requisitos) exige para cada TPSP: (a) acuerdo escrito que cubra security + availability + confidentiality + integrity + privacy, (b) monitoreo del compliance status anualmente, (c) shared responsibility matrix documentada. Cumplimos con 11 vendors activos completamente documentados. Aclaración crítica (verificado visualmente 2026-06-16 en https://www.digitalocean.com/trust/certification-reports): DigitalOcean NO tiene AOC PCI DSS Level 1 Service Provider — tiene PCI-DSS SAQ-A (Zero-Footprint data policy) que cubre únicamente que DO no almacena/procesa/transmite CHD en su environment administrativo. Implicación: DO NO puede ser invocado como "PCI Service Provider" para Fintrixs. Sus attestations reales son: SOC 2 Type II + SOC 3 Type II by Schellman & Company, CIS Benchmarks, Global PRP Certification by Schellman, PCI-DSS SAQ-A (Zero-Footprint), CSA Self-Assessment Level 1 (16 domains, no third-party attested), GDPR + DPA executed. La delegación de PCI 9.x (físico) + 11.2 (wireless) a DO se basa en SOC 2 II by Schellman + CSA Self-Assessment + DPA (práctica aceptada por PCI SSC para cloud providers sin Level 1 SP AOC). (1) Vendors críticos con PCI DSS AOC dedicado: ControlCase (PCI DSS Level 1 SP AOC + SOC 2 II — vendor de QSA+ASV+IDR+PCIUA), Credibanco (PCI DSS Level 1 + Visa+Mastercard certified — acquirer Colombia); (2) Vendor crítico con SAQ-A + SOC 2 by Schellman: DigitalOcean (NO Level 1 SP — infra cloud); (3) Otros vendors críticos: Rapid7 (SOC 2 II + ISO 27001 — InsightIDR via ControlCase); (4) Vendors críticos sin PCI directo: GitHub (SOC 2 II + ISO 27001), Bitwarden (SOC 2 II); (5) Open source vetted via SDLC: Wazuh, GoPhish, Kong; (6) Servicios profesionales: HR Empresa Colombia SAS (background checks Q89); (7) TPSP NUEVO H1 2026: Rapid7 InsightIDR via ControlCase (onboarded 2026-04-10). Para cada vendor: TMPL-014 record en pci_compliance.vendor_tracker table. §5 sample agreement clauses (DO MSA §4.2/4.3, ControlCase MSA §3.1/3.2), §6 monitoring + audit cadence anual, §7 vendor exit en POL-008 §7.


1. Mapeo PCI DSS v4.0

RequisitoDescripciónSección
12.8.1Mantain list of TPSPs§2 inventario 11 vendors
12.8.2Written agreements with TPSPs§3 MSAs + §5 sample clauses
12.8.3Process for engaging TPSPs (due diligence)POL-008 §3 + TMPL-014 workflow
12.8.4Monitor TPSP compliance status annually§4 compliance attestations + §6 audit cadence
12.8.5Information on shared responsibilities§4 per-vendor SRM matrix

2. Inventario completo — 11 vendors activos

Q91-T1

2.1 Tabla maestra (TMPL-014 records)

#VendorServiceRiskStatus
1DigitalOcean, LLCCloud infra (DOKS, DBaaS, Spaces, Cloud Firewall)CriticalActive ✓
2ControlCase ComplianceQSA + ASV + IDR + PCIUA SaaSCriticalActive ✓
3Rapid7, Inc. (via ControlCase)InsightIDR central syslog SIEMCriticalActive ✓ (since 2026-04-10)
4CredibancoAcquirer + payment processor ColombiaCriticalActive ✓
5GitHub, Inc.Source code + CI/CD (Actions)HighActive ✓
6Bitwarden, Inc.Credential vault CTOHighActive ✓
7Wazuh, Inc.SIEM stack (open source — community + commercial)MediumActive ✓
8GoPhishOpen source phishing sim (self-hosted)LowActive ✓
9Kong Inc.Open source API gateway (self-hosted)LowActive ✓
10HR Empresa Colombia SASBackground check servicesMediumActive ✓
11Coalfire (DO's QSA — indirect)PCI attestation for DOLowIndirect (no direct contract)

2.2 Vendor exclusions (out of scope)

Vendors no en alcance para este Q91 porque no acceden al CDE ni soportan la entrega del servicio:

VendorRazón
Google (Gmail)Email del CTO solamente
Stripe (test PANs only)Solo para tests de tokenización; no procesamiento real
WhatsApp BusinessCliente comm, no CDE
Personal bankingNo relacionado con la operación de Fintrixs

3. Vendor critical — DigitalOcean (sample completo)

Q91-T2

3.1 TMPL-014 record DigitalOcean

Vendor ID:                  VND-2024-001
Legal name:                 DigitalOcean, LLC
Commercial name:            DigitalOcean
Vendor type:                IaaS / SaaS
Country of incorporation:   USA (NYSE: DOCN)
Primary PoC:                Account Management Team
Security PoC:               [email protected]
Account manager:            (Enterprise tier)

─── SERVICES ───────────────────────────────────
Service category:           Cloud infra
Service description:        Kubernetes (DOKS) + Managed PostgreSQL + Droplets +
                            Spaces (S3) + Cloud Firewall + VPC
Data accessed:              CHD (within DOKS apps + DBaaS prod)
Systems accessed:           Direct CDE (entire infra)
Network access path:        DO maintains infra; CTO accesses via API/console

─── CONTRACTUAL ────────────────────────────────
MSA effective date:         2024-08-15
MSA expiration date:        Auto-renew annually
MSA renewal type:           Auto-renew
DPA in place:               Yes (Data Processing Agreement)
DPA last updated:           2025-09-10 (GDPR + CCPA addendum)
SLA tier:                   Production (99.99% on critical services)
SLA uptime:                 99.99% DBaaS, 99.9% Droplets
Liability cap:              12 months fees (per MSA §8)
Termination notice:         60 days
Audit rights clause:        Yes (MSA §4.3) — via SOC 2/SOC 3/CSA Self-Assessment request

─── COMPLIANCE (verificado visualmente 2026-06-16) ────────
Trust Center URL:           https://www.digitalocean.com/trust/certification-reports

PCI DSS Level 1 SP AOC:     ❌ NO — DO no es PCI Level 1 Service Provider
PCI-DSS SAQ-A:               ✓ Yes — Zero-Footprint data policy
                              "DO commits to NOT storing, processing, or
                               transmitting cardholder data within our
                               administrative environment"
                              (texto literal del Trust Center)

SOC 2 Type II:               ✓ Yes — issued by Schellman & Company
SOC 3 Type II:               ✓ Yes — issued by Schellman & Company
SOC 2 download:              https://cloud.digitalocean.com/trust/security-reports
CIS Benchmarks:              ✓ Yes — CIS Foundations + CIS Services
Global PRP Certification:    ✓ Yes — certified by Schellman
CSA STAR Level 1:            ✓ Yes (Self-Assessment, not 3rd-party attested)
                              16 cloud-specific domains
GDPR + DPA:                  ✓ Executed (https://www.digitalocean.com/legal/data-processing-agreement)
HIPAA eligibility:           ✓ Yes (eligibility — no BAA universal)
DORA eligibility:            ✓ Yes
ISO 27001:                   NOT listed in DO Trust Center
ISO 27017 / 27018:           NOT listed
FedRAMP:                     NOT listed

─── ACK ────────────────────────────────────────
Vendor compliance ack:      MSA §4.2 — commitment a security program SOC 2 II
Reference clause:           MSA §4.2 (Security) + §4.3 (Audits) + DPA executed
Last ack date:              2024-08-15 (MSA signature) + DPA renewal 2025-09-10
Re-attestation due:         Annual (auto-renewal)
PCI delegation basis:       SOC 2 II by Schellman + CSA Self-Assessment + DPA
                            (DO no es PCI Level 1 SP — solo SAQ-A zero-footprint)
                            Práctica aceptada por PCI SSC para cloud providers
                            que no son Level 1 SP.

IMPORTANT NOTE:              DO PCI-DSS SAQ-A NO se puede invocar para heredar
                            controles PCI de CHD. SAQ-A solo certifica que DO
                            no toca CHD en su env administrativo. Para Fintrixs,
                            esto significa que SOMOS 100% responsables PCI por
                            todos los workloads en DOKS, DBaaS, Spaces.

─── RISK ──────────────────────────────────────
Risk score:                  Critical
Risk justification:          Entire infra hosting CDE; single-cloud risk; multi-tenant SaaS
Annual review date:          2026-08-15
Last incident with vendor:   None

3.2 Shared responsibility matrix con DigitalOcean

PCI ReqResponsabilityNotes
1.x Network firewallsSharedDO = perimeter Cloud Firewalls; Fintrixs = K8s NetworkPolicies + intra-VPC config
2.x ConfigurationsSharedDO = hypervisor + DBaaS managed; Fintrixs = K8s configs + app configs
3.x CHD storageFintrixsDBaaS at-rest encryption (DO); design + key mgmt (Fintrixs)
4.x Encryption transitSharedDO provides VPC private network; Fintrixs uses TLS 1.2+
5.x Anti-malwareFintrixsDOKS nodes per Fintrixs config (Falco + Wazuh)
6.x SDLCFintrixsAll code + deployment by Fintrixs
7.x Access controlSharedDO console = DO MFA; K8s/DBaaS RBAC = Fintrixs
8.x AuthenticationSharedDO account = DO MFA; service accounts = Fintrixs
9.x PhysicalDigitalOceanDC physical security (Q60)
10.x LoggingSharedDBaaS logs (DO); app logs (Fintrixs); SIEM (Fintrixs)
11.x TestingSharedDO does their own pentest; Fintrixs does theirs for app layer
12.x Security policyFintrixsAll policies by Fintrixs

3.3 Sample MSA clauses (DigitalOcean)

DigitalOcean MSA v2025-03-15 — Cláusulas relevantes:

§ 4.2 (Security)
"DigitalOcean shall maintain a comprehensive information security program
designed to protect Customer Data and to comply with applicable laws,
including PHYSICAL, ADMINISTRATIVE, and TECHNICAL safeguards consistent
with industry standards."

§ 4.3 (Audits)
"DigitalOcean shall provide Customer with copies of its CURRENT
attestation reports (SOC 2 Type II, SOC 3, CSA STAR) upon written request,
subject to applicable confidentiality terms (NDA)."

(Note: DigitalOcean is NOT a PCI DSS Level 1 Service Provider. They have
PCI-DSS SAQ-A (Zero-Footprint) which only certifies that DO does not handle
CHD in their own administrative environment. Compliance verification for
Fintrixs use is via SOC 2 Type II by Schellman & Company + CSA Self-Assessment
Level 1 + DPA. Verified visually at Trust Center 2026-06-16.)

§ 4.5 (Data Processing Addendum)
"Customer may execute the DPA to govern processing of Personal Data, in
accordance with GDPR (EU 2016/679) and CCPA (Cal. Civ. Code §1798.100)."

§ 8 (Limitation of Liability)
"Liability cap: amounts paid in the twelve (12) months prior to the
incident."

§ 11 (Termination)
"Either party may terminate this Agreement upon 60 days' written notice."

4. Compliance attestations summary

Q91-T3

4.1 Tabla consolidada

#VendorPCI DSSSOC 2 IIISO 27001ISO 27017ISO 27018Trust Center
1DigitalOceanSAQ-A only (NOT Level 1 SP)✓ Schellman✓ Self-Assessdigitalocean.com/trust
2ControlCaseLevel 1 SP✓ (2025)controlcase.com/trust
3Rapid7— (via ControlCase)✓ (2025)trust.rapid7.com
4CredibancoLevel 1 SP ✓ + Visa/MCcredibanco.com
5GitHub— (no CHD)✓ (2025)trust.github.com
6Bitwarden— (no CHD)✓ (2025)bitwarden.com/security
7Wazuh— (open source)wazuh.com (vetted via Q37)
8GoPhish— (open source)(vetted via Q37)
9Kong— (self-hosted)— (open source)(vetted via Q37)
10HR Empresa ColombiaISO 27001 ✓(CRA registered Colombia)
11Coalfire(assistor general)coalfire.com

4.2 Status code summary

Vendor críticoBase de delegación PCIAttestation valid untilNext renewal
DigitalOceanSOC 2 II by Schellman + CSA Self-Assessment + DPA (NO Level 1 SP — solo SAQ-A)SOC 2 2026-Q42026-12
ControlCasePCI DSS Level 1 SP AOC2026-Q32026-09
CredibancoPCI DSS Level 1 + Visa/MC2026-Q42026-11

Coverage: 11/11 vendors con attestation o documentación vigente. Importante: 2 vendors con PCI DSS Level 1 SP AOC dedicado: ControlCase + Credibanco. DigitalOcean tiene PCI-DSS SAQ-A (Zero-Footprint — solo cubre su env administrativo, no CHD handling para clientes). La delegación de PCI 9.x + 11.2 a DO se basa en SOC 2 Type II by Schellman & Company + CSA Self-Assessment Level 1 + DPA. Práctica aceptada por PCI SSC para cloud providers que no son Level 1 SP. Implicación crítica: Fintrixs es 100% responsable PCI por workloads en DOKS, DBaaS y Spaces — DO solo provee infraestructura, no servicio PCI.


5. Sample agreement clauses extraídas

Q91-T4

5.1 ControlCase MSA — Security Clauses

ControlCase Master Services Agreement v2024-01-01

§ 3.1 (Confidentiality)
"ControlCase shall protect Customer Data with at least the same degree of
care as it uses to protect its own confidential information, but not less
than a reasonable standard of care."

§ 3.2 (PCI Compliance Specific)
"ControlCase confirms its PCI DSS Level 1 Service Provider status for the
services provided under this Agreement (QSA + ASV + InsightIDR managed +
PCIUA awareness training). Annual attestation reports shall be provided
to Customer."

§ 4.1 (Data Processing Agreement)
"For Personal Data processed on behalf of Customer, ControlCase shall act
as Data Processor per GDPR Article 28."

§ 5 (Security Incidents)
"ControlCase shall notify Customer of any Security Incident affecting
Customer Data within 24 hours of discovery, providing reasonable details."

§ 7 (Audit Rights)
"Customer may request a copy of the SOC 2 Type II report annually."

5.2 GitHub Enterprise Terms — Relevant Clauses

GitHub Enterprise Cloud — Customer Terms (relevante para Fintrixs)

§ 4.3 (Security Standards)
"GitHub shall maintain security controls consistent with SOC 2 Type II
attestation. Customer may request the most recent SOC 2 report under NDA."

§ 4.4 (Customer Data)
"Customer Data is owned by Customer. GitHub does not use Customer Data
for training AI models without explicit consent."

§ 6.2 (Subprocessors)
"GitHub uses subprocessors (Microsoft Azure for infrastructure) and
maintains an up-to-date list at https://github.com/site/dpa."

5.3 Bitwarden Business Terms

Bitwarden Business Subscription Agreement v2024

§ 5 (Security)
"Bitwarden maintains zero-knowledge architecture: customer master passwords
and encryption keys are never stored on Bitwarden servers."

§ 6 (Attestations)
"Annual SOC 2 Type II audit conducted by an independent firm.
Report available under NDA via [email protected]."

6. Annual monitoring + audit cadence

Q91-T5

6.1 Annual review calendar 2026

MonthVendorAction
AprCredibancoAnnual MSA review + PCI status check
Jun(this cycle)TMPL-014 templates emitted + tracker populated
AugDigitalOceanAnnual MSA + SOC 2 II Schellman + SAQ-A + CSA Self-Assess + DPA refresh
SepControlCaseAnnual review + SOC 2 II report request
OctGitHubAnnual review + SOC 2 II report
NovWazuh + GoPhish + KongOSS dependency audit (Q37 SDLC)
DecBitwarden + Rapid7Annual review + SOC 2 II

6.2 Trigger automation

TriggerAction
pci_valid_until <= NOW() + 60 daysEmail reminder CISO + procurement
soc2_last_report > NOW() - 14 monthsRequest new SOC 2 report
msa_expiration_date <= NOW() + 90 daysInitiate renewal
New vendor proposedPOL-008 §3 due diligence triggered
Vendor security incident reportedPOL-007 §5 + vendor escalation

7. Vendor exit + decommission

Q91-T6

7.1 Exit triggers

TriggerAction
Vendor PCI attestation expira sin renewalSuspend access + accelerated migration
Vendor security incident severity CriticalActivate IRP (POL-007 §5) + risk assessment
Vendor M&A → new entityRe-evaluate due diligence + new MSA
Service no longer neededStandard decommission

7.2 Decommission checklist (POL-008 §7)

Day 0:    Notice of termination sent
Day 7:    Access list audit + revocation plan
Day 14:   Access revoked (API tokens, accounts, IPs allowlisted)
Day 30:   Data export + verification
Day 60:   Data deletion confirmation + certificate of destruction
Day 90:   Final MSA closure + archive records (7 años retention)

7.3 Historical decommissions (none in H1 2026)

No vendor offboarded en H1 2026. All 11 vendors permanecen activos.


8. Vendor risk dashboard

Q91-T7

8.1 Risk distribution

Risk scoreCountVendors
Critical4DigitalOcean, ControlCase, Rapid7, Credibanco
High2GitHub, Bitwarden
Medium2Wazuh, HR Empresa Colombia
Low3GoPhish, Kong, Coalfire (indirect)

8.2 Hot list — vendors a monitorear

VendorReason
Rapid7 (NEW 2026-04-10)Recently onboarded — needs 6-month check
CredibancoAnnual renewal Q4 2026
DigitalOceanSingle-cloud concentration risk

9. Cómo el QSA verifica cada entregable

Solicitado por QSADónde se prueba
Acuerdo de servicios vigente (seguridad/disponibilidad/conf/integridad)§3 DO + §5 ControlCase + GitHub + Bitwarden sample clauses
Estado de cumplimiento (normativas/estándares)§4 11/11 vendors attestation table
Lista de requisitos seguridad cada vendor maneja§3.2 DO shared responsibility matrix (sample); other vendors in tracker §2
Acuerdos§3.3 + §5 (textual MSA quotes)

10. Vínculo con otros controles

Documentación Confidencial — Solo para uso interno y auditoría PCI DSS