A storage contract is signed with one company. The system it delivers is usually run with help from several others: a colocation provider holding the racks, a support organization staffed across time zones, a monitoring service collecting metrics, third-party components embedded in the product, and a contractor who arrives to swap failed drives. Each sits inside the boundary the contract was meant to define, and most are named nowhere in it.
Procurement questions about sovereignty tend to focus on the location of the primary data center, the easiest fact to establish and the least likely to be wrong. The harder facts concern who can reach the system, from where, and under whose employment. Those facts change during a contract, often unannounced, because they are operational decisions for the vendor rather than contractual ones.
The objective is not to forbid subcontracting, which is unrealistic, but to make the full set of parties visible, constrain what each can reach, and secure the right to be told before the set changes.
Hosting is the first layer. A vendor offering a managed or hosted deployment is usually reselling capacity in someone else's facility, and the operator of that facility controls physical access to the racks and the media in them. The questions are which entity runs the site, where it is, and what happens to a drive that fails.
Support is the second and most often overlooked. Follow-the-sun coverage means a case opened in the evening may be picked up by an engineer on another continent, who needs diagnostic material and sometimes the live system. The mechanics of that access are the subject of remote support access, but the procurement question comes first: which entities employ support staff, and in which countries do they work.
Then come the quieter parties. Telemetry and monitoring platforms are often third-party services rather than vendor-operated systems, and what they receive is a matter of configuration, which makes whether logs cross data boundaries a question for evaluation rather than for deployment. Products embed third-party software with their own update channels. Hardware maintenance contracts are held with organizations that dispatch field engineers, and those engineers handle media.
Most vendors publish a subprocessor list, and most published lists are too thin to use. A name and a headquarters country does not establish where processing occurs, what the party does, or what it can reach. A usable entry names the legal entity, the country the relevant staff or systems operate in rather than where the company is registered, the function performed, the categories of data involved, and whether access is to object content, metadata, operational telemetry or physical media.
Two further items are worth insisting on. The first is whether a party can reach data routinely or only under specific circumstances, since these are different risks and vendors often conflate them. The second is onward subcontracting, because a support partner using a staffing agency, or a hosting provider subcontracting facility maintenance, extends the chain beyond the published list. Flow-down obligations exist to stop the list ending one layer too early.
Requirements written as questions produce better answers than requirements written as assertions, because a question that cannot be answered exposes what a checkbox would hide. Asking a vendor to confirm that data stays in a jurisdiction invites a yes. Asking which entities can open an administrative session, from which countries, and what record is kept, produces either a specific answer or a visible gap. The broader framing of these requirements is covered in data sovereignty RFP requirements.
Ask for answers as artifacts rather than assurances. A subprocessor list, a diagram of outbound destinations, a support access policy and a component inventory are documents a vendor either has or does not. Scoring their presence and specificity separates vendors who have considered the question from those meeting it for the first time in the response.
| Party | What they can typically reach | What to require contractually |
|---|---|---|
| Hosting or colocation provider | Physical access to racks, media and in some cases network paths | Named sites and operating entity, notice before a site change, media disposal terms |
| Support organization | Diagnostic bundles, and interactive sessions on live systems | Countries where support staff work, scoped accounts, session records kept by the customer |
| Telemetry or monitoring service | Metrics, logs, configuration, and often object and bucket names | Field-level description of what is transmitted, storage region, a local-only or opt-out mode |
| Embedded third-party software | Whatever the product reaches, plus its own external update calls | Component inventory with suppliers, update source, ability to disable outbound calls |
| Hardware maintenance contractor | Physical media during replacement and return | Named entity, drive retention or on-site destruction, chain of custody records |
| Cloud tiering or recovery target | Object content written to a second platform | Named provider and region, with the same obligations flowed down in full |
A subprocessor list is a snapshot, and its value depends on what happens when it changes. Notification is the minimum, and it should specify a period before the change takes effect, long enough to assess the new party. Whether the period offered is sufficient depends on how quickly the organization can complete an assessment and, if the answer is unfavorable, act on it.
Notification without a remedy is of limited use. The clause worth negotiating gives a right to object on reasonable grounds, an obligation on the vendor to offer an alternative or keep the existing arrangement for that customer, and a right to terminate without penalty if neither is possible. Termination rights only mean something where the data can be recovered on the timeline the notice period allows, which ties the clause to proving that data can be retrieved.
Subscribing to the vendor's change notifications is a small step that is frequently skipped, and a list published on a web page with no push mechanism should be checked on a calendar rather than trusted to arrive.
RING is software-defined storage deployed on standard x86 servers in the customer's own facility. That deployment model removes several of the parties described above from the picture entirely, since there is no hosting provider holding the racks and no managed service operator with standing access. The hardware supplier and its maintenance contractor remain, as does the storage vendor's support organization, so those relationships still warrant the questions above.
Because the system runs on customer-owned infrastructure, physical location, network boundaries, key management and operational access are set by the customer rather than inherited from a provider's architecture. Metrics and logs are emitted in a form that can be kept local, so what is shared externally becomes a decision rather than a default.
Multi-site placement is configured by the operator, so where copies live is recorded in the customer's own configuration rather than in a service catalog. In procurement terms, that moves a set of questions out of the vendor questionnaire and into the customer's change control, where they can be evidenced directly.
Keep a register of parties, not a filed copy of the vendor's list. One row per organization that can reach the system, recording the entity, the country its relevant staff or systems operate in, what it can access, the contractual basis, and the date last confirmed. That register is what an auditor, a regulator or an internal risk function will ask for, and it is far easier to maintain incrementally than to reconstruct.
Reconcile it annually and at every renewal against the vendor's current published list and against what the system shows: which external endpoints it contacts, which accounts have logged in, and which support cases involved remote sessions. Gaps between the contractual picture and the observed one are the findings worth pursuing.
Treat a change notification as a task with an owner and a deadline, not an email to acknowledge. Record what was assessed, what was decided and by whom, so the objection right stays exercisable rather than lapsing through inaction.