Skip to main content
Back to Changelog
June 10, 2026
Console

Nested Third-Party Relationships

Third parties can now nest to any depth, not just one level of sub-vendor, so subprocessors of subprocessors are representable.

Nested Third-Party Relationships

Third-party relationships used to support exactly one level: a vendor and its direct sub-vendors. Anything past that had no home in the data model.

Third parties can now nest to arbitrary depth. Each third party carries a reference to its parent, and the console, API, and CLI (prb third-party list --level N) all understand levels beyond the first. If your vendor’s subprocessor has its own subprocessor, that relationship is now representable instead of flattened.

This also cleans up how sub-vendor links work generally: they’re just a parent reference on the third party itself now, instead of a separate link/unlink relationship to manage.

ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert