Choosing AI Tools Safely: A Vendor Evaluation Framework
A practical framework for evaluating AI vendors on security, compliance, and data handling. The questions to ask before you sign.
A practical framework for evaluating AI vendors on security, compliance, and data handling. The questions to ask before you sign.
AI tools are appearing everywhere, from standalone SaaS products to features embedded in software you already use. The rush to adopt means many organisations are using AI tools without properly evaluating how they handle data.
This creates real risk. Your customer data, employee records, financial information, or proprietary knowledge could be stored in unknown locations, used for model training, or accessible to the vendor's staff.
For every AI tool your organisation considers, evaluate these five areas:
Before signing up for any AI tool that will handle business data:
| Question | Ideal answer | Red flag |
|---|---|---|
| Is data used for model training? | No, with opt-out by default | "By default, yes" with no opt-out |
| Where is data stored? | Specific region (e.g., AWS Sydney) | "Various global data centres" |
| Can data be deleted? | Yes, on request with confirmation | "Data may be retained indefinitely" |
| Third-party access? | No sub-processors without disclosure | Unnamed third-party processing |
| Encryption? | AES-256 at rest, TLS 1.2+ in transit | "Encryption where appropriate" |
Our approach: Self-hosted or Bedrock-based AI means your data never leaves your AWS account. No vendor training, no third-party access, full audit control.
Ask the author
Ask it here and it comes straight to the founder. No sales call, no obligation, and a real answer even if the answer is that you do not need us.
Kasun Wijayamanna
Founder, replies within one business day
Tell us what you're working on. We'll come back with a practical recommendation and clear next steps.
Thanks for reaching out. We will get back to you within one business day.
See what else we do