Data
Where does information go?
Ask what is collected, whether prompts train models, where data is processed, who can access it, how long it remains and how deletion is proven.
Open responsible source ↗Control
Can you restrict and observe use?
Check identity, role permissions, audit logs, tool restrictions, retention settings and administrative controls.
Change
What can change without your approval?
Require notice for model, policy, subprocessors and material feature changes. Define when your organisation must re-evaluate.
Exit
Plan the end before signing
Confirm data export, deletion, configuration portability and how dependent workflows continue during transition.
FREQUENTLY ASKED
Two points worth making clear
Should we ban confidential data from every AI tool?+
Start with a clear data classification and approved service list. Some enterprise services support controlled use; consumer tools may not fit the same data.
What is the strongest vendor evidence?+
Evidence you can inspect: contract terms, architecture and control documentation, relevant test results, incident process and verifiable deletion or export steps.