Blog · Data custody

Twelve questions to ask an AI vendor about your data

Before you put real work into an AI product, ask the vendor where your data goes, who can read it, how long it is kept, whether it trains anything, and how you get it out again. The twelve questions below cover those points in plain language, with notes on what a good answer sounds like.

Send them in writing and ask for written replies. A vendor with a sound design will usually answer quickly and specifically. Vague or shifting answers are information too.

Where the data goes

1. What exactly leaves my device, and when? Ask about background activity as well as the moment you press send: indexing of files, telemetry, crash reports, and sync. A good answer lists categories of data and the trigger for each. The guide on what gets sent to an AI provider explains what a single request can contain.

2. Which AI model providers and other sub-processors receive my content? Many AI products send your prompt on to a separate model provider, and use other companies for hosting, logging and support. Ask for the current list, what each one receives, and how you will be told when the list changes.

3. In which countries is my data stored and processed? Storage location and processing location can differ. If you have residency requirements, ask whether a region can be fixed by contract, not only by default.

Who can read it

4. Who at your company can see my content, and under what conditions? Look for named roles, a need-to-know rule, logged access, and a process for support cases that requires your permission. "Nobody" is rarely true of a hosted service; "only these roles, in these cases, and it is logged" is a better answer.

5. Is my content reviewed by people or automated systems for safety or quality? Providers often monitor for abuse. Ask what is sampled, who reviews it, how long those samples are kept, and whether any plan turns this off.

6. Where are my sign-ins and API keys stored? If you paste a key into a vendor's website, the vendor holds a copy. If the application keeps it in your operating system's keychain and calls the provider directly, the vendor does not. Both designs exist. Know which you are buying. See where your AI keys and logins should live.

What is done with it

7. Is my content used to train or improve any model, yours or a third party's? Ask whether this is opt-in or opt-out, whether the setting is per user or per organisation, whether it differs between plans, and whether it covers feedback such as thumbs-up ratings. Ask the same question about each sub-processor.

8. How long are prompts, outputs, files and logs kept? Retention often differs between the main database, application logs, backups and any safety review queue. Ask for each. Ask whether you can set a shorter period.

9. What happens when I delete something, and when I leave? A good answer gives a time limit for deletion from live systems and from backups, and says whether you can get written confirmation. Ask whether derived data, such as search indexes and embeddings, is deleted too.

Control and recovery

10. Can I export everything, in a format I can use elsewhere? Ask to see an export before you commit. Open formats such as plain text, Markdown, CSV and JSON are a good sign. Ask whether history, comments and attachments are included, and whether export still works after your subscription ends.

11. What can the AI do without a person approving it, and what record is kept? This matters most for agents that can send messages, change files, spend money or call other systems. Ask which actions need approval, whether that can be configured, and whether there is a log showing what was proposed, who approved it and what happened. The guide on human in the loop approvals covers what good approval design looks like.

12. How will I be told about a security incident, and what independent assurance do you have? Ask for the notification commitment in the contract, not only on a web page. Ask which audits or certifications the vendor holds, such as a SOC 2 report or ISO 27001 certification, what scope they cover, and whether you can see the report. An audit of the hosting provider is not an audit of the vendor.

How to read the answers

Sign of a sound answer Sign of trouble
Specific: names, periods, locations "We take security very seriously"
Matches the contract and data processing terms Differs between the sales call and the paperwork
Distinguishes between plans One answer for every plan, when the terms say otherwise
Admits limits plainly Claims that nothing is ever stored anywhere
Offers documents without a fight Needs several escalations for a simple answer

Two further points. First, a marketing page is not a commitment. What binds the vendor is the contract, the data processing agreement and the published terms for your plan, so check that the answers appear there. Second, terms change. Note the date of the answers you were given, and check the provider's current terms again at renewal.

Questions to ask yourselves

A vendor's answers only help if you know your own position.

  • What kinds of data will staff actually put into this tool? Think about what people do under deadline, not what the policy says.
  • Which of those are personal data, client confidential, or covered by a sector rule?
  • Who in your organisation decides that a tool is approved, and where is that written down?
  • Have you told staff, in one page, what may and may not go into AI tools?

The guide on data custody in AI gives a simple framework for this, and local-first AI explained describes a design that shortens several of the answers above.

This list is general information, not legal advice. For contracts and regulated data, involve your own legal or compliance adviser.

Where Prism fits

Prism Desktop is designed so that several of these questions have short answers. Each agent signs in with the owner's own AI account, Prism never holds that login, keys stay in the computer's keychain, and only the prompt goes to the AI provider the person chose. Agents propose; people approve a finding, a merge, an email or an install, and decisions are recorded. The security page has more detail.

Keep reading