Question pack
Security & Data Protection Question Pack
Security, privacy, certifications and supply chain — the four modules that decide whether an AI vendor survives your review board.
What it de-risks
- ▸Separate real certifications from claimed ones, with the evidence request written for you.
- ▸Interrogate data handling, residency, and retention against your own compliance posture.
- ▸Surface subprocessors and model-provider dependencies before they become your incident.
- ▸Give security review a scored questionnaire instead of a vendor slide deck.
What is inside
4 corpus modules, at both RFI and RFP depth, in canonical order. Every question ships with what a strong answer looks like, the red flags to watch for, a response-format hint, and a default weight you can tune.
- Security
- Data protection & privacy
- Compliance & certifications
- Third-party & supply chain
Sample questions
Which independent security certifications and attestations do you currently hold (e.g., SOC 2 Type II, ISO/IEC 27001, FedRAMP), and what is the renewal cadence for each?
Why it matters — Third-party attestations are the baseline evidence that a vendor's security program is independently validated rather than self-asserted. Certifications also indicate the vendor's willingness to undergo recurring external audit, which is a strong proxy for ongoing security investment.
Describe how your platform identifies, classifies, and minimizes personal data (including special-category data) that customers submit as prompts, files, or context to your AI features.
Why it matters — PII minimization is a core GDPR principle and a baseline expectation for any AI tool that ingests customer content. Vendors without a clear classification approach typically default to retaining everything, which expands the buyer's breach blast radius and DSAR burden.
Do you hold a current SOC 2 Type II attestation covering the product offered? Provide the report date, observation period end date, and the name of the auditing firm.
Why it matters — SOC 2 Type II is a foundational attestation for enterprise SaaS vendors, demonstrating that security controls have been independently audited over a period of time. A missing, stale (report older than 15 months), or in-flight-only attestation can indicate immature controls or an unwillingness to undergo scrutiny.
Provide your current sub-processor list. For each sub-processor, include its legal name, processing purpose, country/region of data processing, and the specific categories of customer data it may process (e.g., content, metadata, telemetry). This can be provided as a public URL or a direct attachment.
Why it matters — Buyers need a current, detailed sub-processor inventory to complete data-protection impact assessments and vendor risk reviews. Understanding the location, purpose, and data access for each sub-processor is essential for this. A public, machine-readable list signals maturity; a list gated behind sales is a red flag.
One-time purchase · Word questionnaire + Excel scoring matrix · Downloads immediately · Itemized receipt and perpetual organization license · Free account required at checkout