Skip to content

Evaluating AI Vendors for Security

Questions to ask before adopting third-party AI products and APIs, covering data, security, compliance and resilience.

Editorial team 1 min read

Buying AI products and services brings their security posture into your organisation. Assess vendors before adopting.

Data Handling

  • Is our data used to train models? Can we opt out?
  • How long are prompts, files and outputs retained?
  • Where is data stored and processed?
  • Who at the vendor can access it?

Security Controls

  • Certifications and independent audits.
  • Encryption, access control and single sign-on support.
  • Logging and audit trails available to customers.
  • Vulnerability management and incident notification commitments.

AI-Specific Questions

  • How are prompt injection and data leakage addressed?
  • How are connected tools and integrations permissioned?
  • How are model changes communicated and tested?
  • Is there red-teaming or third-party testing?

Compliance

  • Support for privacy regulations relevant to you.
  • Contractual terms on data processing and liability.

Resilience

  • Uptime commitments, rate limits and fallback options.
  • Exit plan: can you export data and switch vendors?

Ongoing Review

Reassess periodically and when vendors change models, terms or features.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025