Security & trust · 9 min read

Questions to ask any AI vendor about your data

This is the list we would want a buyer to hold us to. Ask it of us, and of everyone else you are considering.

Access

Start with reach, because reach determines every other risk.

  • What exactly will you be able to read once I connect this, and can I narrow it?
  • Can I grant access to one mailbox, folder or record set rather than the whole account?
  • How do I withdraw access, and what happens to work in progress when I do?

Handling

Then ask what happens to the information once it has been read.

  • Is my business content used to train models, by you or by anyone you send it to?
  • Where is it processed, and which third parties see it in the course of a normal request?
  • How long is it retained, and can I ask for deletion?

Action

Anything that can act on your behalf needs a separate set of answers.

  • Which actions can happen without a person approving them?
  • How is an action classified as needing approval, and can I change that classification?
  • Is there a record of who approved what, and can I export it?

Accountability

Finally, ask what happens when something goes wrong.

  • How would I find out about a mistake, and how quickly?
  • What do you consider your responsibility versus mine?
  • What certifications do you actually hold today, as opposed to intend to hold?

How to read the answers

Precision is the signal. A vendor who can describe their boundaries in specific terms is easier to trust than one who answers with reassurance. Vagueness about training data, retention or unattended action is worth treating as a no until it becomes a yes in writing.

For our part: we publish no certifications we do not hold, and we would rather tell you a capability is planned than describe it as live.

Written by the 8ORA team. We publish no customer names, figures or certifications we cannot evidence.