Skip to content

Data protection questions a buyer should ask any AI product vendor

A usable questionnaire on subprocessors, training, retention, human access, approval, and exit for operators and controllers at 10-200 person firms.

nox.markets5 min read
  • security
  • privacy
  • procurement
  • compliance

A controller will open the data-handling page before the catalog. That is the correct order. This list is the same inspection, turned into questions you can paste into a vendor email or a security questionnaire.

The point is not to sound like a 2,000-person GRC team. The point is to refuse tools you cannot explain to an insurer, a customer's MSA, or a CFO who asks what happens if the model books a wrong amount.

"The model is usually right" is not an answer. Neither is a padlock illustration. Neither is a certification the vendor does not hold. SOC 2 Type II, ISO 27001, and HIPAA may appear as a dated roadmap. They may not appear as present-tense achievements unless the report or attestation exists.

Use the answers in writing. If they exist only on a call, they will not file.

1. Scope: what do you read?

  • Which objects do you read (invoices, mailboxes, CRM records, bank transactions, files in Drive)?
  • Is that list on the product page, or only in a deck?
  • What do you explicitly not read? A named refusal is part of the product.
  • Do you need full mailbox access when the job is one AP inbox?

If they cannot bound the read, you cannot bound the risk.

2. Write path: what do you change?

  • Which systems do you write to, and is it a draft or a posted object?
  • For finance, is human approval the default? Who is the named approver?
  • Can a run create a payment, a wire, a payroll submit, or a legal filing? If yes, stop and escalate. Those should be refusals for most catalog jobs.
  • Is every action logged, and can we export the log?

Work that lands in your system of record stays yours. Work that only lives in the vendor's UI is a second set of books.

3. Where does it run?

  • Is this hosted (runs on the vendor), connected (runs on the vendor, acts in our tools via OAuth we can revoke), or self-hosted (we run it, they license it)?
  • Which cloud region? US only? EU residency available, from which plan tier?
  • Is processing in memory for connected jobs, or do you persist documents? For how long?
  • If our constraint is "this file does not leave the network," do you actually offer self-hosted, or only a slide about VPC?

Deployment language should be those three words, not a diagram that means "trust us."

4. Subprocessors and model providers

  • Publish the live subprocessor list, including every model provider.
  • If a company is not on that list, will you contractually refrain from sending our data there?
  • Which region does each subprocessor process in?
  • How do you notify us when the list changes?
  • Are we allowed to object, and what is the timeline?

Your customer's MSA will ask this. If you cannot answer, you cannot sign that customer.

5. Training and secondary use

  • Is customer data used to train your models?
  • Is customer data used to train the model provider's models?
  • Is there a contractual no-training clause, or only a marketing sentence?
  • Do you use our data to improve evals that other customers benefit from? If yes, is that anonymized, and is it optional?
  • Do you sell, broker, or advertise using the content of our books or mailboxes?

The acceptable default for this buyer is: customer data is not training data. Anything softer needs a lawyer.

6. Human access (theirs)

  • Can a vendor employee see our documents in the ordinary course of support?
  • Is access logged, time-bounded, and customer-gated?
  • What is the process when we open a ticket that includes an invoice PDF?
  • Do you use production data in development?

If "a human can see it" is yes, write down when and why. Hidden human review is still processing.

7. Retention, deletion, and cancellation

  • Retention window per product, in days or months, on the product page.
  • What is deleted on cancel, and on what schedule?
  • Does cancellation unwind objects already in QuickBooks, HubSpot, or the mailbox? It should not. Those are yours.
  • Can we export configuration and output history in open formats before we leave?
  • For self-hosted, is there a source-escrow clause if the vendor shuts down?

"What if you shut down" is a fair question. Ridicule is a signal.

8. Identity, access, and tenancy

  • SSO: Google/Microsoft, SAML from which tier, SCIM from which tier?
  • Encryption in transit and at rest — name the protocols. TLS 1.3 and AES-256 are answers. "Bank-grade" is not.
  • Tenant isolation: how is our workspace separated?
  • Unlimited seats does not mean unlimited admin. Who can connect OAuth and who can approve postings?

9. Accuracy, money, and audit

  • Where is the eval: dataset type, sample size, date, measured task-success or error rate, named failure mode? (Ask this of every vendor. nox.markets does not publish one yet; the card has a time-saved rationale and a named failure mode.)
  • Do extracted fields cite the source document?
  • Is there a confidence threshold below which the item cannot auto-post?
  • Can we produce an audit trail for a specific invoice or vendor over a date range?
  • Who is accountable when it is wrong — a named vendor, or "the model"?

First-party catalogs at least make the last question one word. A directory of abandoned listings does not.

10. Certifications and paper

  • SOC 2 Type II: in progress, report expected [date], or completed (only if true)?
  • ISO 27001: same rule.
  • HIPAA: only if you are actually a BAA vendor for a defined product. Do not collect a logo.
  • DPA: standard paper vs custom. Custom is a Scale/Enterprise conversation for most vendors; that should be explicit.
  • Insurance: cyber policy, and whether they will complete your customer's questionnaire.

11. Operational failure

  • What happens when the model provider deprecates a model? Do we get a changelog or a migration project?
  • Per-run credit or spend ceilings: will it stop, or bill in silence?
  • Pause control in the dashboard. Revoke OAuth in our IdP. Both should work without a ticket.
  • Support: first-response time, and whether the relationship is with the marketplace or a third-party seller.

How to score the answers

You are not looking for poetry. You are looking for:

  • Bounded read/write
  • A live subprocessor list
  • No-training in contract language
  • Human approval where money moves
  • Export and revoke
  • Honest certification status
  • A named owner when it is wrong

If a vendor fails the rebuild test — you cannot explain the answers to your CFO in ten minutes — do not put PII in the tool. Keep the ChatGPT seat for work that never leaves a paste box. That is a worse process, and it is still better than an unanswerable one.

nox.markets's public sentence on certifications is: SOC 2 Type II is in progress. We will not imply a report we do not have. Customer data is not used to train models. Finance products default to human approval. Connected products use scoped OAuth you can revoke. Self-hosted exists for files that must not leave the network. The product page, not this article, is the source of truth per SKU.

More from the blog