An eighty-question security questionnaire often yields less than a twenty-minute conversation. Not because the questions are bad, but because they are completed by someone other than the person who knows, and because "yes" to "is data encrypted" carries almost no information.
These are six questions that do yield something, with what to listen for in each.
1. Where does processing run, and which jurisdiction governs you?
Two questions asked as one, and they need separate answers.
A vendor can run in Frankfurt and still be a US company. The data centre location then does not answer the question of which government can compel disclosure.
Usable answer: the processing region, the domicile of the contracting entity, and whether a parent company sits in a different jurisdiction. Evasion: "we host in the EU".
2. What do you retain, for how long, and can I configure it?
Ask separately about three things: conversation content, technical logs, and attachments. They frequently carry different periods.
Also ask what happens between deletion and permanent removal. At most services that gap is around thirty days.
Usable answer: a period per category, and whether it is configurable per tier. Evasion: "no longer than necessary".
3. Is my input used for training, and does that differ by tier?
The second half is the important half. At nearly every provider the answer differs between the free account, the business account and the API.
Push further: does the commitment cover only model training, or also human review and quality assurance? Those are different things, as set out in what "we don't train on your data" actually means.
Usable answer: per tier, with a pointer to where it sits contractually. Evasion: "we do not train on customer data".
4. Who inside your organisation can access my data, and why?
Almost every provider has a basis for reviewing conversations on suspicion of abuse. That is not suspicious, it is normal, and it belongs in your assessment rather than outside it.
Usable answer: under what circumstances, by which role, with what approval, and whether it is logged. Evasion: "access is strictly limited".
5. Who are your sub-processors, and am I notified of changes?
AI services frequently lean on other AI services. A tool that works on your PDFs may call a third party's model internally. That third party is then part of your chain.
Usable answer: a current list with role and location, plus a notification period and a right to object. Evasion: a list with no date on it.