Blog — Trust & Safety

What to check before trusting
an AI vendor with your data.

Confirm four things in writing before you sign: the model provider's data-retention policy, encryption in transit and at rest, whether private deployment is available if you need it, and whether data residency and deletion are configurable. Here's why each one actually matters, not just what to tick off.

Rajeish Mata Oct 10, 2026

Does the model provider train on your data?

This is the one most teams forget to ask, because it's one step removed from the vendor in front of them — it's a property of whichever underlying model provider the vendor builds on. Without a zero data-retention agreement, your inputs can be used to improve a public model, which means patterns from your data effectively leave your control even if the raw data itself isn't shared anywhere.

Ask directly: "Which model providers do you use, and do you have zero data-retention agreements with them?" A vendor that can't answer that question specifically, by provider, hasn't actually checked.

In transit and at rest, as a baseline.

Encryption in transit (TLS 1.3 or equivalent) and at rest (AES-256 or equivalent) should be the default, not an enterprise-tier add-on you have to negotiate for. The follow-up question that actually separates vendors: who holds the encryption keys? If the vendor controls key management end to end, revoking their access later is harder than it should be.

Can it run in your environment, not just theirs?

Not every use case needs it, but if yours involves regulated or highly sensitive data, ask whether VPC, on-premise, or private-cloud deployment is actually available — not just mentioned on a sales call. "Technically possible" and "something we've actually shipped for a client" are different claims, and only one of them is useful to you.

Configurable, not a policy statement.

If you have regulatory requirements — GDPR, data residency rules, sector-specific retention limits — ask whether processing and storage location is configurable at the infrastructure level, and whether there's a defined deletion pipeline for honouring a right-to-erasure request. "We take data protection seriously" in a sales deck is not an answer to either question.

Ask forNot
The specific model providers used, and their retention terms"We use leading AI providers"
The encryption standard, in writing (e.g. TLS 1.3, AES-256)"Enterprise-grade encryption"
A reference deployment matching your required model (VPC/on-prem)"That's technically possible"
A defined data-deletion pipeline and timeline"We take privacy seriously"

Where this fits.

This is the checklist our own Trust & Safety page is built to answer directly — VPC/on-premise deployment, zero data-retention model providers, TLS 1.3 and AES-256 encryption, and configurable data residency and deletion. Worth holding any vendor, including us, to the same four questions.

Get started

Want to see how
we answer these four?

Book a 30-minute call, or go straight to the detail on our Trust & Safety page.