Vendor Data Questions That Matter
~8 min read
Estimated time: ~8 min read — for the in-app brief plus opening the primary source.
What this is
A concise RFP/questionnaire set on training rights, subprocessors, retention, residency, encryption, incident notice, and customer isolation.
A concise RFP/questionnaire set on training rights, subprocessors, retention, residency, encryption, incident notice, and customer isolation.
- Is customer content used to train foundation or vendor models? Default and opt-out?
- Where is data stored and processed? Subprocessors list?
- Retention and deletion on exit? Logs of prompts/outputs?
- Human review of prompts by vendor staff?
Next action: Security questionnaires can be theater. These questions target the terms that actually determine your residual risk.
Deep dive
Is customer content used to train foundation or vendor models? Default and opt-out?
Where is data stored and processed? Subprocessors list?
Retention and deletion on exit? Logs of prompts/outputs?
Human review of prompts by vendor staff?
Change notification if model behavior or hosting changes materially?