Security template

AI vendor security questionnaire

Ask questions that can be answered with bounded explanations and supporting evidence, then review those answers in the context of the proposed use.

Architecture and boundaries

  1. Describe the service architecture and trust boundaries relevant to customer data.
  2. Identify material hosting, model, integration, and subprocessor dependencies.
  3. Explain how customer environments and data are logically separated.

Identity and access

  1. Describe administrative access controls, authentication, authorization, and review.
  2. Explain how privileged actions are logged and monitored.
  3. Describe employee access approval and removal practices.

Data protection

  1. Describe encryption for data in transit and at rest.
  2. Explain retention, deletion, backup, and restoration behavior.
  3. State whether customer data is used to train or improve models and what controls apply.

Secure development

  1. Describe code review, testing, dependency management, and vulnerability handling.
  2. Explain how production changes are approved and monitored.
  3. Describe relevant security testing and the scope and date of available evidence.

Incidents and resilience

  1. Describe detection, response, customer notification, and lessons-learned practices.
  2. Explain service continuity assumptions and recovery objectives relevant to the use case.
  3. Identify customer controls or integrations needed for safe operation.

AI-specific controls

  1. Describe controls for prompt injection, unsafe tool use, data leakage, and harmful output.
  2. Explain evaluation methods and known limits for the intended use.
  3. Describe model or system changes that are communicated to customers.

Evidence note

Request evidence proportionate to the use case. A policy, report, test result, or certification has a defined scope and date; it should not be interpreted as a blanket security assurance.