A sub-processor is any third party a software vendor uses to process customer personal data on its behalf: the cloud host, the email delivery service, the support tooling. Under GDPR, vendors must disclose their sub-processors, flow the same protections down by contract, and tell customers before adding new ones.
Reading a sub-processor list is one of the fastest security reviews available: it shows where your data actually lives and which companies, in which jurisdictions, can touch it. Short, boring lists of major providers are what good looks like.