Skip to content

Question pack

Security & Data Protection Question Pack

Security, privacy, certifications and supply chain — the four modules that decide whether an AI vendor survives your review board.

$99 one-time250 questions · 4 modules

What it de-risks

  • Separate real certifications from claimed ones, with the evidence request written for you.
  • Interrogate data handling, residency, and retention against your own compliance posture.
  • Surface subprocessors and model-provider dependencies before they become your incident.
  • Give security review a scored questionnaire instead of a vendor slide deck.

What is inside

4 corpus modules, at both RFI and RFP depth, in canonical order. Every question ships with what a strong answer looks like, the red flags to watch for, a response-format hint, and a default weight you can tune.

  • Security
  • Data protection & privacy
  • Compliance & certifications
  • Third-party & supply chain

Sample questions

  • Which independent security certifications and attestations do you currently hold (e.g., SOC 2 Type II, ISO/IEC 27001, FedRAMP), and what is the renewal cadence for each?

    Why it matters Third-party attestations are the baseline evidence that a vendor's security program is independently validated rather than self-asserted. Certifications also indicate the vendor's willingness to undergo recurring external audit, which is a strong proxy for ongoing security investment.

  • Describe how your platform identifies, classifies, and minimizes personal data (including special-category data) that customers submit as prompts, files, or context to your AI features.

    Why it matters PII minimization is a core GDPR principle and a baseline expectation for any AI tool that ingests customer content. Vendors without a clear classification approach typically default to retaining everything, which expands the buyer's breach blast radius and DSAR burden.

  • Do you hold a current SOC 2 Type II attestation covering the product offered? Provide the report date, observation period end date, and the name of the auditing firm.

    Why it matters SOC 2 Type II is a foundational attestation for enterprise SaaS vendors, demonstrating that security controls have been independently audited over a period of time. A missing, stale (report older than 15 months), or in-flight-only attestation can indicate immature controls or an unwillingness to undergo scrutiny.

  • Provide your current sub-processor list. For each sub-processor, include its legal name, processing purpose, country/region of data processing, and the specific categories of customer data it may process (e.g., content, metadata, telemetry). This can be provided as a public URL or a direct attachment.

    Why it matters Buyers need a current, detailed sub-processor inventory to complete data-protection impact assessments and vendor risk reviews. Understanding the location, purpose, and data access for each sub-processor is essential for this. A public, machine-readable list signals maturity; a list gated behind sales is a red flag.

One-time purchase · Word questionnaire + Excel scoring matrix · Downloads immediately · Itemized receipt and perpetual organization license · Free account required at checkout