CMD+RVL sub-processors
This page lists the third-party providers CMD+RVL may use to operate the website and deliver scoped services. It is written for security, privacy, and procurement review.
Provider use depends on the specific website function, deployment pattern, and customer workflow. For a security package or engagement-specific review, contact drew@cmdrvl.com or use the contact page.
The public website uses Google Analytics 4 for aggregate traffic measurement only after a visitor allows analytics. Every browser request stays on cmdrvl.com: both the analytics script and its measurement beacons are proxied through our own CDN, so the browser never connects to googletagmanager.com or google-analytics.com. This keeps the site rendering inside locked-down corporate networks that block third-party domains. It does not change where the data goes. The measurement data is still processed by Google, which is why Google is listed as a sub-processor above.
Until approval, the Google tag is not loaded and no analytics measurement request is sent. Do Not Track and Global Privacy Control override a stored approval. Advertising storage, advertising user data, advertising personalization, Google Signals, and advertising-personalization signals are disabled. Requests necessarily include network information such as an IP address; Google states that Google Analytics 4 does not log or store individual IP addresses.
Current sub-processors
- Cloud service providers
Amazon Web Services (AWS), Microsoft Azure
RoleCloud infrastructure, storage, and deployment services.
Data categoryApplication data, operational metadata, and service logs when required for a scoped deployment.
- Identity management providers
Auth0 by Okta
RoleAuthentication, authorization, and identity management.
Data categoryAccount identifiers, authentication events, and access-control metadata.
- Website analytics providers
Google (Google Analytics 4)
RoleConsent-based aggregate public-website traffic measurement. Served through a first-party proxy on cmdrvl.com, so the browser makes no third-party connection. Not used for advertising or remarketing.
Data categoryConsented page views, referrer, approximate geography, and device or browser type. The site does not send names, email addresses, account user IDs, or advertising identifiers.
What runs on this site
A complete inventory of every script, form, and integration on cmdrvl.com, what each collects, and where the data goes. This is the whole list; if a flow is not here, it does not exist on the site.
- Analytics
Google Analytics 4, consent-gated
Loads only after a visitor selects Allow analytics. Collects page views, referrer, approximate geography, and device type. Off by default, Do Not Track and Global Privacy Control override a stored approval, and advertising storage, Google Signals, and personalization are permanently disabled. Data is processed by Google as the sub-processor listed above.
- Forms
Contact and lead forms
The contact page, homepage note, outcome scoping wizard, and PBIX report request collect name, company, email, and a message. Submissions are relayed as email to our inbox through our own AWS infrastructure and are not stored in a database. They are not used for advertising, enrichment, or AI training.
- Uploads
PBIX auditor files
Uploaded Power BI files are processed in memory, structural metadata is returned to your browser, and the file is discarded. Report data values are not returned or stored, and no AI model processes the file.
- Everything else
No other collection exists
No chat widgets, no advertising pixels, no social trackers, no third-party fonts or CDNs. Every request your browser makes stays on cmdrvl.com.
This inventory is enforced, not just published: an automated browser test runs on every release and fails the build if any page makes a request to a third-party host.
Review notes
- Sub-processor relevance is scoped during security review.
- Customer deployment patterns can change which providers apply.
- Website analytics are separate from scoped customer outcome work.
- Questions and DDQ requests should include the workflow being reviewed.
Sub-processor questions
What is a sub-processor?
A sub-processor is a third-party provider that may process data on behalf of CMD+RVL while helping operate the website or a scoped service.
Which CMD+RVL sub-processors are currently listed?
CMD+RVL currently lists Amazon Web Services, Microsoft Azure, Auth0 by Okta, and Google (Google Analytics) as sub-processors for cloud hosting, identity management, and website analytics.
Does every engagement use every listed provider?
No. Provider use depends on the website function, deployment pattern, and scoped customer workflow. Security review can confirm which providers apply to a specific engagement.
Does the website use visitor data for AI training, advertising, or enrichment?
No. Form submissions are relayed as email and not stored in a database, uploaded files are processed in memory and discarded, no AI model processes visitor data, and advertising features are permanently disabled in the analytics configuration.
Who should I contact with sub-processor questions?
Sub-processor questions can be sent to drew@cmdrvl.com. Security package requests can also be routed through the contact page.
Need provider details for a diligence package or procurement review? Send the workflow, deployment pattern, and review deadline.
Contact security