Software companies
How to answer AI questions in customer security questionnaires
By SourceX Editorial · Updated
Short answer
To answer AI questions in customer security questionnaires, give a scoped, factual answer for each data category, name the AI providers involved, and attach evidence such as the DPA, the sub-processor list or an AI use policy. The rule: never write an absolute promise, such as no data is ever used for AI, unless a control enforces it.
Key takeaways
- AI questions cluster around training on customer data, AI features and model providers, retention, opt-outs, agent access and third-party sharing.
- Answer by data category, because customer content, usage data and company-owned records often have different true answers.
- Every answer should point to evidence a reviewer can check, such as the DPA, the sub-processor list or a settings screenshot.
- Questionnaire answers can become contract terms, so counsel reviews any answer that reads as a commitment.
- One dated answer library keeps sales, security and legal giving the same answer.
What AI questions are customers asking vendors now?#
Customers now ask software vendors a fairly stable set of AI questions: whether customer data trains any model, which AI features exist and which providers power them, how those providers handle data, whether customers can opt out, and how AI agents are controlled inside the vendor's systems. The questions show up as a new section in standard questionnaires or as a separate AI addendum from procurement.
Behind every variant sits one worry: will our data end up somewhere we did not agree to? Answers that address that worry directly, with specifics, close reviews faster than long policy excerpts.
- Training: is customer data used to train, fine-tune or evaluate models, yours or anyone else's?
- Features: which product features use AI, and can they be switched off per account?
- Providers: which model providers act as sub-processors, and under what terms?
- Retention: do providers store prompts and outputs, and under what limits?
- Access: what can AI agents and internal tools read, and who reviews that access?
- Sharing: is any data licensed, sold or shared with third parties for AI?
- Governance: who approves new AI uses, and how are AI incidents handled?
Question bank: model answers and the evidence to attach#
The question bank pairs common AI questions with an answer pattern and the evidence a reviewer will expect. Adapt each pattern to what is true for your company; a polished answer that is not true does more damage than a plain no.
Choose evidence the customer can keep. Public documents such as the sub-processor list and help articles can simply be linked, while internal policies are better shared as a short excerpt or under NDA, with the version date visible so the reviewer knows what was current when you answered.
| Question | Answer pattern | Evidence to attach |
|---|---|---|
| Do you use customer data to train AI models? | State the position for each data category: customer content, usage data, company-owned records | DPA clause, AI use policy, relevant contract excerpt |
| Which AI providers process our data? | Name each provider, the feature it supports and the data it receives | Sub-processor list with locations and change dates |
| Do providers retain or train on prompts and outputs? | Describe your contract terms with each provider, not the provider's marketing | Summary of provider terms or DPA reference |
| Can we turn off AI features or opt out? | Explain the account-level setting and its default | Admin settings screenshot or help article |
| How do you control AI agents' access to systems? | Describe service accounts, permission scopes and access reviews | Access review records and policy excerpt |
| Do you share or license data with third parties for AI? | Say what is shared, what is excluded and under which terms | Data sharing policy, customer FAQ, approval record |
| How do you assess new AI uses? | Name the approval owner and the review steps | AI governance procedure and risk assessment template |
How to write AI answers that stay true#
AI answers stay true when they are scoped, dated and tied to a control. Most questionnaire trouble comes from answers that were accurate when written and quietly became false after a product release or a new model provider.
- Scope each answer: name the data category, the product and the provider instead of answering for everything at once.
- Avoid absolute words such as never and all unless a technical or contractual control enforces them.
- Match the DPA, sub-processor list, privacy notice and trust center, because reviewers compare them.
- Date every answer in the library and set a review trigger, such as a new AI feature or provider.
- Send answers that read as commitments to counsel, since attached questionnaires can become contract terms.
- Escalate unknowns internally instead of guessing in the customer's spreadsheet.
How does data licensing change your answers?#
Data licensing changes questionnaire answers only where it touches what the question asks about. A company that licenses de-identified internal engineering history, and no customer data, can still truthfully say that customer data is not used to train AI models or shared with third parties for that purpose.
The answer has to be precise, though. A blanket statement that the company shares no data of any kind for AI training would be false once it licenses its own records, so split the answer: customer data on one line, company-owned records on another. Where customers have opted in to a specific use, describe that scope and the consent record behind it.
Expect follow-up questions about how customer content is kept out of licensed records. A short description of the review, the de-identification steps and who approved release usually answers them.
Who should own the AI answer library?#
The AI answer library should have one owner, usually the security lead, with named approvers for answers that carry legal or product risk. Sales engineers pull from the library rather than drafting new answers under deadline.
| Answer type | Drafts | Approves | Review trigger |
|---|---|---|---|
| Training and data use | Security lead | General counsel | Contract template or policy change |
| AI features and settings | Product manager | Security lead | New feature or changed default |
| Model providers | Engineering lead | Security lead and counsel | Provider added, removed or terms changed |
| Agent and tool access | IT or platform lead | Security lead | New agent, integration or permission scope |
| Third-party sharing and licensing | General counsel | CEO or delegated signer | Any new data sharing or licensing project |
Illustrative: a construction scheduling software company rebuilds its AI answers#
Illustrative: a fictional construction scheduling software company receives questionnaires from general contractors that now include an AI section. Its sales engineers had been answering from memory, and two answers contradicted each other: one said no AI was used anywhere, while another described a schedule-risk feature built on an external model provider.
The security lead builds an answer library in the company's compliance tool, splits the training answer by data category, adds the model provider to the public sub-processor list and links each answer to evidence. Counsel approves the answers that read as commitments. When the company later licenses de-identified internal Jira history, the sharing answer is updated that week to name company-owned records and confirm that customer content is excluded.
Reviews stop stalling on contradictions, and the company can show any customer what changed and when.
How SourceX fits into questionnaire answers#
SourceX scopes packages around records a company can license, which is usually company-owned material with personal and customer details removed. That keeps the questionnaire answer simple: customer data stays out unless customers have agreed otherwise.
For each package, the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. A security lead can file it as the internal evidence behind a sharing or licensing answer without exposing deal terms to customers.
Frequently asked questions
Should we publish our AI answers on a trust center?
Publishing the most common answers, such as the training position and the list of AI providers, cuts repeat questions and keeps sales aligned. Keep the public version short, dated and identical in substance to the DPA and privacy notice, because customers will treat it as a commitment.
What if a questionnaire asks for a commitment we cannot make?
Answer truthfully and offer the commitment you can make, such as an account-level opt-out or a narrower restriction on customer content. Flag it to counsel, because the customer may try to turn the question into a contract clause. A clear partial answer beats a yes you cannot keep.
Do standard questionnaires such as SIG or CAIQ cover AI?
Coverage varies by version, and many customers add their own AI section on top. Keep AI answers in your own library regardless of format, then map them into each questionnaire. That keeps answers consistent whether a request arrives as a standard template or a custom spreadsheet.
How do we answer questions about AI coding assistants our engineers use?
Describe which tools are approved, what code and data they may see, whether customer data can appear in prompts, and the provider terms on retention and training. If engineers handle customer data while debugging, explain the controls that keep it out of prompts. Check plan tiers too: GitHub says it does not use Copilot Business or Enterprise customer data to train AI models, while its documentation states that from April 24, 2026, interactions on individual Copilot plans may be used for training unless the user turns that setting off.
What evidence do reviewers trust most for AI answers?
Reviewers trust evidence that shows a control working, not only a policy. A settings screenshot showing an AI feature off by default, a dated sub-processor list, a contract excerpt with the model provider and an access review record carry more weight than a paragraph restating the policy.
Sources
- GitHub's Copilot Trust Center FAQ states that GitHub does not use Copilot Business or Copilot Enterprise customer data to train AI models. Source
- Starting April 24, 2026, interactions on individual Copilot plans may be used to train and improve AI models, and users can turn this off with the 'Allow GitHub to use my data for AI model training' setting. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.