Retrieve the full vendor register including criticality, DPA status, and DORA Article 28 fields.
The list-vendors endpoint returns your full vendor register — feeding GDPR Article 28 transparency, DORA Article 28-30 ICT third-party risk, and ISO 27001 A.5.19 supplier inventory. Use it to drive procurement-side dashboards, due-diligence reports, or to mirror the register into a parent organization’s GRC tool.Documentation Index
Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
Use this file to discover all available pages before exploring further.
| Query parameter | Values | Use |
|---|---|---|
criticality | critical / important / standard | DORA-style criticality slicing |
processesPersonalData | true / false | GDPR Art. 28 register subset |
ictService | true / false | DORA Art. 28 ICT-vendor subset |
category | freeform string | Industry / category match |
country | ISO 3166-1 alpha-2 | Filter by country of registration |
perPage is 50, max 200. For organizations with hundreds of vendors, paginate with page and stop when meta.page === meta.totalPages.
dpaStatus: signed / pending / not_required. Filter by dpaStatus=pending to surface vendors still missing DPAs — useful for an end-of-quarter DPA cleanup sweep.
subProcessors array. Each sub-processor entry includes name, country, and processing-purpose category.
id, name, country, categorycriticality, ictService, processesPersonalDatadpaStatus, dpaSignedAt, dpaUrllastReviewedAt, nextReviewDuesubProcessors[] — sub-processor disclosurestransferMechanism — for non-EU vendors handling personal dataAPI key for authentication
Organization ID (required for session auth, optional for API key auth)