Data protection questions a buyer should ask any AI product vendor
A usable questionnaire on subprocessors, training, retention, human access, approval, and exit for operators and controllers at 10-200 person firms.
- security
- privacy
- procurement
- compliance
A controller will open the data-handling page before the catalog. That is the correct order. This list is the same inspection, turned into questions you can paste into a vendor email or a security questionnaire.
The point is not to sound like a 2,000-person GRC team. The point is to refuse tools you cannot explain to an insurer, a customer's MSA, or a CFO who asks what happens if the model books a wrong amount.
"The model is usually right" is not an answer. Neither is a padlock illustration. Neither is a certification the vendor does not hold. SOC 2 Type II, ISO 27001, and HIPAA may appear as a dated roadmap. They may not appear as present-tense achievements unless the report or attestation exists.
Use the answers in writing. If they exist only on a call, they will not file.
1. Scope: what do you read?
- Which objects do you read (invoices, mailboxes, CRM records, bank transactions, files in Drive)?
- Is that list on the product page, or only in a deck?
- What do you explicitly not read? A named refusal is part of the product.
- Do you need full mailbox access when the job is one AP inbox?
If they cannot bound the read, you cannot bound the risk.
2. Write path: what do you change?
- Which systems do you write to, and is it a draft or a posted object?
- For finance, is human approval the default? Who is the named approver?
- Can a run create a payment, a wire, a payroll submit, or a legal filing? If yes, stop and escalate. Those should be refusals for most catalog jobs.
- Is every action logged, and can we export the log?
Work that lands in your system of record stays yours. Work that only lives in the vendor's UI is a second set of books.
3. Where does it run?
- Is this
hosted(runs on the vendor),connected(runs on the vendor, acts in our tools via OAuth we can revoke), orself-hosted(we run it, they license it)? - Which cloud region? US only? EU residency available, from which plan tier?
- Is processing in memory for connected jobs, or do you persist documents? For how long?
- If our constraint is "this file does not leave the network," do you actually offer self-hosted, or only a slide about VPC?
Deployment language should be those three words, not a diagram that means "trust us."
4. Subprocessors and model providers
- Publish the live subprocessor list, including every model provider.
- If a company is not on that list, will you contractually refrain from sending our data there?
- Which region does each subprocessor process in?
- How do you notify us when the list changes?
- Are we allowed to object, and what is the timeline?
Your customer's MSA will ask this. If you cannot answer, you cannot sign that customer.
5. Training and secondary use
- Is customer data used to train your models?
- Is customer data used to train the model provider's models?
- Is there a contractual no-training clause, or only a marketing sentence?
- Do you use our data to improve evals that other customers benefit from? If yes, is that anonymized, and is it optional?
- Do you sell, broker, or advertise using the content of our books or mailboxes?
The acceptable default for this buyer is: customer data is not training data. Anything softer needs a lawyer.
6. Human access (theirs)
- Can a vendor employee see our documents in the ordinary course of support?
- Is access logged, time-bounded, and customer-gated?
- What is the process when we open a ticket that includes an invoice PDF?
- Do you use production data in development?
If "a human can see it" is yes, write down when and why. Hidden human review is still processing.
7. Retention, deletion, and cancellation
- Retention window per product, in days or months, on the product page.
- What is deleted on cancel, and on what schedule?
- Does cancellation unwind objects already in QuickBooks, HubSpot, or the mailbox? It should not. Those are yours.
- Can we export configuration and output history in open formats before we leave?
- For self-hosted, is there a source-escrow clause if the vendor shuts down?
"What if you shut down" is a fair question. Ridicule is a signal.
8. Identity, access, and tenancy
- SSO: Google/Microsoft, SAML from which tier, SCIM from which tier?
- Encryption in transit and at rest — name the protocols. TLS 1.3 and AES-256 are answers. "Bank-grade" is not.
- Tenant isolation: how is our workspace separated?
- Unlimited seats does not mean unlimited admin. Who can connect OAuth and who can approve postings?
9. Accuracy, money, and audit
- Where is the eval: dataset type, sample size, date, measured task-success or error rate, named failure mode? (Ask this of every vendor. nox.markets does not publish one yet; the card has a time-saved rationale and a named failure mode.)
- Do extracted fields cite the source document?
- Is there a confidence threshold below which the item cannot auto-post?
- Can we produce an audit trail for a specific invoice or vendor over a date range?
- Who is accountable when it is wrong — a named vendor, or "the model"?
First-party catalogs at least make the last question one word. A directory of abandoned listings does not.
10. Certifications and paper
- SOC 2 Type II: in progress, report expected [date], or completed (only if true)?
- ISO 27001: same rule.
- HIPAA: only if you are actually a BAA vendor for a defined product. Do not collect a logo.
- DPA: standard paper vs custom. Custom is a Scale/Enterprise conversation for most vendors; that should be explicit.
- Insurance: cyber policy, and whether they will complete your customer's questionnaire.
11. Operational failure
- What happens when the model provider deprecates a model? Do we get a changelog or a migration project?
- Per-run credit or spend ceilings: will it stop, or bill in silence?
- Pause control in the dashboard. Revoke OAuth in our IdP. Both should work without a ticket.
- Support: first-response time, and whether the relationship is with the marketplace or a third-party seller.
How to score the answers
You are not looking for poetry. You are looking for:
- Bounded read/write
- A live subprocessor list
- No-training in contract language
- Human approval where money moves
- Export and revoke
- Honest certification status
- A named owner when it is wrong
If a vendor fails the rebuild test — you cannot explain the answers to your CFO in ten minutes — do not put PII in the tool. Keep the ChatGPT seat for work that never leaves a paste box. That is a worse process, and it is still better than an unanswerable one.
nox.markets's public sentence on certifications is: SOC 2 Type II is in progress. We will not imply a report we do not have. Customer data is not used to train models. Finance products default to human approval. Connected products use scoped OAuth you can revoke. Self-hosted exists for files that must not leave the network. The product page, not this article, is the source of truth per SKU.
More from the blog
The hidden costs of tool sprawl in mid-size companies
The 15th SaaS login is rarely the fee. It is questionnaires, champions who leave, and no shared context. How 10–200 person companies should gate the next AI SKU.
When the model provider retires the model: dependency risk you can actually plan for
Model deprecation is scheduled maintenance. What breaks, who pays to retest, and which contract terms a buyer should require in writing before you buy.
How to measure automation honestly when time-saved numbers are usually invented
Why vendor hour-savings fail a controller rebuild test, and how volume times minutes times loaded rate stays honest without fake case studies.
