Vendor posture

Every tool’s compliance, on the record.

Your tool register is the natural home for each vendor’s compliance posture. Record certifications, flag sub-processors, and note where each tool hosts data, right beside its seats, cost, and owner.

Figma
compliance

Certifications

SOC 2ISO 27001HIPAAPCI DSS
Sub-processor

Data region

EU · Frankfurt

Every tool you run is a vendor with a compliance posture, and your tool register is the obvious place to keep it. On each tool’s Compliance tab you record its certifications, whether it’s a sub-processor for your customers’ data, and where it hosts that data.

So the same record that proves who has access to a tool also captures whether that tool is one you can defend to an auditor or a customer.

What you can record

Certifications per tool

Mark each tool’s attestations, SOC 2, ISO 27001, HIPAA, PCI DSS, and more, so your vendor inventory shows at a glance which tools meet the bar your own customers hold you to.

Sub-processors & data residency

Flag the tools that act as sub-processors for personal data and note where each one hosts it. The groundwork for your own GDPR Article 28 and 30 obligations, kept current beside the tool, not in a separate spreadsheet.

One record, two jobs

Compliance lives on the same tool entry as its seats, cost, and owner, so the register you keep for access doubles as the vendor-posture inventory a security review asks for.

In depth

Your vendor inventory, where access already lives

Security questionnaires and audits don’t just ask who has access. They ask which vendors hold your data and whether those vendors are themselves compliant. Keeping that in a side spreadsheet means it drifts. Driply keeps it on the tool, so the moment you catalog a tool you have a place for its certifications, its sub-processor status, and its data-hosting region.

Per-tool compliance tracking is available on every plan, including Free, it’s part of the core register, not a paid add-on. (The aggregated, exportable sub-processor / DPA register is a Business capability, see below.) What you record is what you assert: Driply gives each tool a structured home for its posture; it doesn’t audit your vendors for you or verify their certifications on your behalf.

On Business and up, Driply rolls the per-tool data up into a dedicated sub-processor / DPA register, the kind you attach to your own DPA or Article 30 record, and exports it as CSV or PDF. Tagging sub-processors on each tool stays free on every plan; the aggregated, exportable register is the Business capability.

The result, The access record and the vendor-posture inventory, kept in one place.

FAQ

Questions, answered.

What compliance information can I track per tool?
Certifications such as SOC 2, ISO 27001, HIPAA, and PCI DSS, whether the tool is a sub-processor for personal data, and where it hosts data, all on the tool’s Compliance tab, beside its seats, cost, and owner.
Does Driply verify a tool’s certifications?
No. Driply gives each tool a structured place to record the posture you’ve confirmed; it doesn’t independently audit vendors or verify their certifications for you.
How does this help with GDPR?
Flagging which tools are sub-processors and where they host data builds the groundwork for your own Article 28 and 30 obligations. On Business and up, Driply auto-generates an exportable sub-processor / DPA register from it.
Is compliance tracking a paid feature?
Per-tool compliance tracking is free on every plan, including Free. The aggregated, exportable sub-processor / DPA register is a Business feature.

Put your access on the record.

Free for up to 10 people and 20 tools. No credit card.

Start free