The small-business AI vendor security and privacy checklist.
Before an AI vendor receives customer data or system access, get clear answers on data use, deletion, location, access, incidents and exit. Score the evidence, not the sales promise. If the vendor cannot explain where information goes, who can reach it or how you leave, keep the pilot limited to public, low-risk data.
Ask these before the pilot becomes business infrastructure.
Score each answer: 0 = unknown or unacceptable, 1 = partly answered, 2 = clear and supported by evidence.
Will our inputs or outputs train models?
Ask whether training is off by default, opt-out or unavoidable—and whether the rule differs by plan.
How long is data kept and how is it deleted?
Cover prompts, files, outputs, logs, backups and deleted accounts. Ask when deletion is complete.
Where is data stored and processed?
Identify countries, residency options, cross-border transfers and which features change the data path.
Which other companies handle our data?
Request the current list, purpose, locations and how you are notified before material changes.
Is data encrypted in transit and at rest?
Ask what is covered, how keys are managed and whether connected tools or exports create gaps.
Can we control who sees and does what?
Look for roles, least privilege, admin controls, read-versus-write access and rapid offboarding.
Are MFA and SSO supported and enforceable?
Confirm plan requirements, enforcement, recovery, guest access and service-account handling.
Can we see important activity?
Ask about sign-ins, prompts, data access, connector actions, admin changes, exports and log retention.
Can the model or provider change underneath us?
Understand notice, version control, testing, deprecation and whether data moves to another provider.
Do the terms and DPA fit our use?
Review ownership, confidentiality, privacy roles, permitted use, warranties, liability and priority of documents.
What happens when security fails?
Request notification timing, contact path, investigation support, breach responsibilities and recent material history.
Can we export our work and close cleanly?
Confirm formats, cost, timing, connector removal, account deletion and what remains in backups.
Who helps when the workflow stops?
Ask for support channels, response targets, status reporting and escalation appropriate to the business impact.
What can each connection read or change?
Check scopes, inherited permissions, action confirmation, token revocation and prompt-injection safeguards. Ask the vendor to demonstrate the least-privileged scope for your exact use case—not merely describe it.
Can usage and price be controlled?
Understand limits, overages, credits, connector fees, model changes, alerts and a hard way to stop spend.
Do not average away a critical failure. A high total score does not cure an unacceptable answer on sensitive data, access, incident handling or legal authority to use the information.
Ask for documents you can keep.
Terms, DPA and privacy documentation
Include the subprocessor list, retention/deletion policy and documented data-use position for your plan.
Trust centre and assurance summary
Look for current independent certification or assessment scope, plus security and incident contacts.
Admin and connector evidence
Screenshots or live demonstration of roles, MFA/SSO, logs, scopes, confirmations and revocation.
Export and deletion procedure
Get the actual steps, formats, timing, charges and post-termination treatment—not “available on request”.
Hidden risk usually sounds vague.
- “Industry standard” without stating the control or assurance scope.
- Training language changes by page or cannot be tied to your plan and contract.
- No subprocessor list or no notice before material supplier changes.
- Deletion excludes backups or logs without a defined retention period.
- Broad connector scopes with no read-only option or action confirmation.
- No export path until after the contract is signed.
- Security answers only on a sales call and cannot be retained in writing.
Use the number to route the decision—not replace judgment.
| Total | Meaning | Next step |
|---|---|---|
| 24–30 | Most answers are clear and evidenced. | Run use-case, privacy and security review; pilot with minimum access. |
| 16–23 | Material gaps or plan ambiguity remain. | Resolve named gaps in writing before adding business data. |
| 0–15 | The risk cannot be understood well enough. | Do not use beyond public, low-risk experiments. |
Apply stricter thresholds for sensitive information, consequential decisions, customer-facing actions or broad system access.
| Question | Consumer plan | Business or enterprise plan |
|---|---|---|
| Training | Is opt-out required and does it cover every feature? | Is no-training treatment contractual for inputs and outputs? |
| Administration | Can the business manage accounts at all? | Are roles, offboarding, SSO/MFA and logs available on this exact tier? |
| Privacy terms | Are consumer terms appropriate for business and personal information? | Is a DPA available and does it match the intended use and jurisdiction? |
| Retention | Can history be disabled and data deleted? | Can retention be configured, audited and applied to projects, files and logs? |
| Support | Is help limited to self-service? | Is there a security contact, response target and escalation route? |
Ask once. Get the answers in writing.
Subject: Security and privacy questions for [PRODUCT] We are assessing [PRODUCT] for [USE CASE] and expect it may handle [DATA TYPES] or connect to [SYSTEMS]. Please send current documents or links covering: 1. use of our inputs and outputs for model training; 2. retention, deletion, storage/processing locations and subprocessors; 3. encryption, roles, MFA/SSO, logs and connector permission scopes; 4. model/provider change notice, incident notification and support escalation; 5. DPA/contract terms, export/exit process and applicable pricing limits. Please identify which answers depend on plan level or optional settings. We would also like a security contact for follow-up. Thank you, [NAME / BUSINESS]
A vendor decision expires when the product changes.
- Before pilotScore the vendor and approve a narrow use case, data set and access boundary.
- After 30 daysReview actual data, actions, errors, costs and whether the tool remains necessary.
- QuarterlyCheck terms, subprocessors, permissions, users, logs, spend and open incidents.
- On changeReassess after a new model, connector, provider, feature, incident or material workflow.
Questions before approving the vendor.
No. Check what product, controls, dates and locations the assurance covers. Your use case, configuration and connector permissions create risks beyond a certificate.
Possibly for public, low-risk work. Do not assume consumer terms, training treatment, administration or support are appropriate for personal, confidential or regulated information.
Treat unknown as risk. Narrow the pilot to public data with no connections, choose another vendor or obtain specialist advice before proceeding.
OAIC guidance says privacy obligations can apply where generated outputs contain personal information, including inferred or inaccurate information about an identifiable person.
Name one business owner, then involve privacy, security, legal or IT expertise proportionate to the data, decisions, access and impact.
Guidance behind the checklist.
- OAIC: Privacy and commercially available AI products →
- ASD: Guidelines for procurement and outsourcing →
- ASD: AI and ML supply-chain risks and mitigations →
- NIST: AI Risk Management Framework →
- NIST: Generative AI Profile →
This checklist is educational and cannot determine legal compliance or security on its own. Australian privacy obligations depend on the organisation, information and use. Seek qualified advice for higher-risk processing, contracts or regulated work.
Design safer workflows before adding access.
Assess the workflow, data and permissions before the tool.
Aenta can help identify the smallest useful AI setup, map what it needs to access and leave clear human approval points. Request an assessment to decide whether the work belongs in Adoption, Automations, AI Operating System—or should remain manual.
Request an Assessment