Skip to main content
Back to Changelog
May 15, 2026
Console

Vendors Are Now Third Parties

Vendor is now Third Party across the API, CLI, webhooks, and console — a breaking rename that better matches compliance terminology.

Vendors Are Now Third Parties

ZebraByte has renamed the Vendor concept to Third Party everywhere.

This is a breaking change across the full API surface.

What changed

  • GraphQL and MCP: all vendor* fields and types renamed to third_party*
  • Webhook events: vendor:* events are now third_party:*
  • CLI: prb vendor command group renamed to prb third-party
  • Console and Trust page URLs updated accordingly
  • Database snapshot type: VENDORSTHIRD_PARTIES

Why it matters

The rename better reflects what the feature tracks: any third-party service your organization uses, not just traditional vendors. It also aligns the product language with GDPR and SOC 2 terminology used by compliance teams.

What you need to do

If you have automations, scripts, or integrations that use the ZebraByte API or CLI:

  • Update webhook listeners from vendor:* to third_party:*
  • Update prb vendor calls to prb third-party
  • Update any hardcoded GraphQL queries or MCP tool calls referencing vendor fields
  • Update any saved URLs that include /vendor paths

Existing data is migrated automatically. No manual data migration needed.

ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert