What to do
Ask vendors for precise, contract-backed answers about data use, retention, model providers, identity controls, auditability, agent isolation, vulnerabilities, incidents, and deletion. Map every answer to your threat model.
Data and model questions
Ask exactly which content is transmitted, stored, or used for training; which model providers and subprocessors receive it; where processing occurs; and how exclusions, retention, export, and deletion are enforced.
Identity and execution questions
Check SSO, provisioning, role controls, audit logs, service accounts, command approvals, network boundaries, credential handling, and isolation between customers. Ask how administrators restrict agent tools and repositories.
Assurance and lifecycle questions
Request relevant audit reports, penetration-test practices, vulnerability disclosure, incident notification terms, availability commitments, and business-continuity plans. Confirm what happens to data, indexes, tokens, and integrations at offboarding.
- Require evidence for material claims.
- Record exceptions and compensating controls.
- Assign owners and review dates.
- Reassess after major product changes.
Practical checklist
Continue researching
This guide is an editorial framework, not a product endorsement. Recheck vendor documentation and your organization's requirements before making a purchasing or security decision.