Problems/04

Your vendor register describes procurement. Not production.

Build a live processor register from the models and MCP servers that actually receive traffic, including region, data categories, DPA status and the projects behind every call.

The problemLive processor blindnessalso: processor register lag

Live processor blindness is not being able to say which providers and subprocessors receive your data right now, from which region, and under which data classification.

Who asks for this
Data protection officer Privacy Vendor risk Security Procurement
Inspect a processor record All problems
Where it becomes visible

Nobody discovers this problem in a planning meeting

An Article 30 request

The register describes last year of architecture.

A customer asks for the subprocessor list

Procurement answers from a spreadsheet, engineering knows better.

A new SDK ships

It adds a subprocessor nobody assessed.

A provider changes region

The default endpoint moves, and residency claims quietly break.

A DPIA update

Data categories per processor have to be stated, not estimated.

A DPA renewal

Nobody knows whether that vendor still receives traffic at all.

What it costs

The bill arrives as delay, not as an incident

01The register is stale on the day it is signed

Annual surveys cannot track weekly integrations.

02Transfer mechanisms cannot be proven

SCCs on file, no evidence of what actually crossed.

03Deals stall on subprocessor lists

Every enterprise buyer asks, and the answer takes weeks.

04Procurement finds out afterwards

The vendor is live before the assessment starts.

05Incident scope is guesswork

You cannot say what a compromised provider actually held.

Why the usual tooling does not close it

The gap

How obstruo closes it

The control

Registers are gathered by survey, from memory, once a year.
The register is built from real traffic: provider, region, classification, projects.
Each provider dashboard shows only its own slice.
One register across every provider your traffic reaches.
Egress logs show hostnames, not data categories.
Each route carries the data classification and the redaction standard applied.
Spreadsheets have no expiry and no owner.
DPA status, transfer mechanism, review date and owner sit on the record.
An unapproved provider is discovered, not prevented.
Unapproved providers are refused in path, and the attempt is recorded with the project behind it.
The evidence artefact

A processor record that is true at the moment you read it.

This is the shape of the record obstruo produces. It is the same artefact a reviewer, an auditor and an enterprise buyer each ask for, and it exists before they ask.

Append-only Owner named Exportable
Processor record ACTIVE
ProcessorEU model provider
Regioneu-central, pinned by policy
Data receivedpseudonymised prompts, no direct identifiers
Categoriescontract data, claim references
Redaction standardeu-pii-strict v14
Transfer mechanismnone required, EU to EU
DPAon file, signed 2025-11-04, review 2026-11-04
Projects6, owners named on the record
Requests, 30 days812,447
Last call4 minutes ago
provider-x-preview: refused in path, 41 attempts from 2 projects, no DPA on file.
Derived from requests that actually happened. Exportable as an Article 30 extract.
The other three

They arrive together, and the same controls answer them

01
AI evidence debt
Read the problem page
02
Agent authority drift
Read the problem page
03
Policy deployment gap
Read the problem page

Your AI. Your data. Your control.

Bring your current subprocessor list. We will show what a register built from live traffic looks like next to it.

See your live processor exposure See pricing