Skip to content

Software companies

What security questions to ask an AI data buyer before delivery

By SourceX Editorial · Updated

Short answer

Before delivery, ask an AI data buyer fifteen security questions covering where the data will be stored, who can access it, which subprocessors touch it, how long it is kept, how deletion is proven and how fast you will hear about an incident. The answers belong in the contract, because control after handover depends on it.

Key takeaways

  • Ask security questions before the contract is final, so the answers can become obligations.
  • Storage location, access lists and subprocessors decide who can see the data after handover.
  • Ask how deletion will be proven, not only whether it will happen.
  • Incident notice terms should name a timeline, a contact on each side and what a notice must contain.
  • Large datasets can stay in your own storage or ship on encrypted drives instead of being uploaded.

Why ask security questions before delivery?#

Security questions belong before delivery because the handover is the last moment you control the data directly. After that, protection rests on the buyer's practices and on what the contract obliges it to do, so the answers you collect should become contract terms rather than sit in an email thread.

The fifteen questions below fall into five groups. Your CTO or security lead usually asks them, and your counsel makes sure the answers land in the license agreement or its security schedule. A buyer with mature practices will usually answer in writing and may point you to an existing security report or completed questionnaire.

Storage and location: questions 1 to 3#

Storage questions establish where your records will sit, physically and logically. They matter for security and for any data residency commitments in your own customer contracts.

Location questions also connect to provenance standards. The Data & Trust Alliance's Data Provenance Standards list allowed and excluded processing and storage geographies among the use metadata a dataset can carry, alongside license to use and intended use, which gives both sides a shared vocabulary for writing location limits into the record.

Storage and location: questions 1 to 3
QuestionA good answerA red flag
1. Where will the data be stored, by provider and region?A named cloud provider, regions and the account that owns the storageUndecided, or wherever is convenient for the team
2. Will it be kept apart from other suppliers' data?A dedicated bucket or project with its own access policyMixed into a shared data lake from the first day
3. How is it encrypted at rest and in transit?Encryption in both states, with key access controlled and loggedReliance on provider defaults nobody can describe

Access, use and onward sharing: questions 4 to 9#

Access and sharing questions decide how many people, systems and outside companies will touch your records, and for what purpose. Subprocessors include anyone outside the buyer who may handle the data, such as cloud hosts, annotation vendors and evaluation contractors.

Good answers name roles rather than everyone on a research team, describe an approval step and confirm that logs exist. Pay attention to question 6: records licensed to train one kind of model should not quietly become input to unrelated products. The permitted use clause in the license is what gives that answer force.

Annotation and labeling vendors deserve a direct question, because they often involve people outside the buyer's staff working in separate tools. Question 9 overlaps with competitive use terms; counsel will usually want the license to restrict onward sharing of raw data outright and to address models trained on it explicitly.

  • 4. Who will have access, by role, and how is access approved and reviewed?
  • 5. Is access logged, and will logs be shared on request or during an audit?
  • 6. Which systems will the data feed, and is use limited to the purposes in the license?
  • 7. Which subprocessors will receive or access the data, and for which tasks?
  • 8. Will we be notified before a subprocessor is added, and can we object?
  • 9. Will the data, or models trained on it, be shared with affiliates or other companies?

Retention, deletion and proof: questions 10 to 12#

Retention questions set how long the buyer keeps your records and what evidence you receive when it stops.

Deleting raw files is easier to promise than deleting what was learned from them. Ask directly whether trained models are covered, and expect an honest buyer to explain that model weights are treated differently from raw data. The license should say so in plain terms rather than leave it implied.

Retention, deletion and proof: questions 10 to 12
QuestionWhat to ask for in writing
10. How long will raw data be kept, and what triggers deletion?A defined retention period or event, such as the end of the license term
11. Which copies will exist, such as backups, derived datasets and cached samples?A list of copy types and how each one is deleted or aged out
12. How will deletion be proven?A signed deletion certificate naming systems and dates, backed by audit rights

Incident notice and audit: questions 13 to 15#

Incident questions decide how quickly you learn about a problem and what you can do about it.

Notification timing is negotiated deal by deal. What matters is that the contract names a timeline, a contact on each side and the minimum contents of a notice. For question 15, a current independent report such as a SOC 2 report, where the buyer has one, often answers several earlier questions at once.

  • 13. How soon will we be notified of a security incident affecting our data, and through which contact?
  • 14. What will a notice include: scope, records affected, cause and remediation?
  • 15. Can we review evidence of your controls, such as an independent audit report or a completed security questionnaire?

Where each answer belongs in the contract#

Each answer belongs in a specific part of the license, and mapping them before negotiation keeps any of them from being lost between the security review and the final draft. Counsel will adapt the structure to the agreement in front of them; the table shows the usual home for each topic.

Keep the buyer's written answers as an exhibit or in the deal file even after they are turned into terms. If a later dispute turns on what was promised, the original answers show what both sides understood at signing.

Where each answer belongs in the contract
Answer areaUsual place in the license
Storage location and encryptionSecurity schedule, with any geographic limits stated in permitted use
Access roles and loggingSecurity schedule and audit rights
Systems the data feedsPermitted use and restrictions clause
Subprocessors and onward sharingSubprocessor clause with notice and objection rights
Retention and copiesTerm, termination and deletion clause
Deletion proofDeletion certificate requirement and audit rights
Incident noticeSecurity incident notification clause, with named contacts

Illustrative: a procurement software company puts the questions to a buyer#

Illustrative: a fictional procurement software company is preparing to deliver a package of Jira issues, pull requests and support escalations. Before signing, its CTO sends the fifteen questions to the buyer's security team, and the company's counsel tracks which answers must appear in the license.

Most answers come back clear. Two do not: the buyer plans to use an outside annotation vendor it has not yet named, and its deletion process covers primary storage but not backups. The company asks for advance notice and an objection right for new subprocessors, and for backups to age out on a defined schedule with a certificate at the end. Both terms go into the security schedule before delivery is approved.

How SourceX handles security before delivery#

SourceX places these questions in the Approval and Delivery steps of the SourceX five-step transaction. The supplier sees the buyer's answers before approving release, and the agreed terms are recorded with permitted use and release authorization in the SourceX Evidence Packet.

Large datasets stay in the supplier's own storage with controlled access or ship on encrypted drives; SourceX does not host multi-terabyte datasets. That keeps the number of copies small and makes the deletion questions easier to answer.

Frequently asked questions

What if the buyer will not answer some questions?

Treat an unanswered question as information. Some buyers decline to name internal systems or vendors for their own security reasons but will accept contract terms instead. If a buyer will neither answer nor commit contractually on storage, access, deletion or incident notice, pause delivery and review the deal with counsel.

Who on our side should review the answers?

The CTO or security lead reviews technical answers, counsel turns them into contract terms, and the executive approving the license signs off on any remaining risk. In a smaller company one person may cover two roles, but keep the review in writing so the decision can be explained later.

Do these questions replace data processing terms?

No. The questions gather facts; the license agreement and, where personal data is involved, any data processing terms create obligations. Packages are normally prepared so personal and confidential details are removed before delivery, but the privacy laws that may apply are assessed deal by deal with counsel.

Can we avoid uploading the data at all?

Sometimes. For large datasets, delivery can run from your own storage with time-limited, logged access, or on encrypted drives sent to the buyer. Both reduce the number of copies outside your control, and the same retention and deletion questions still apply to whatever the buyer keeps.

Should we ask the questions again after delivery?

Yes, at renewal and whenever the buyer's circumstances change, such as a new subprocessor, an acquisition or a move to a different cloud provider. At the end of the term, ask for the deletion certificate the contract requires and check that it names the systems and copies listed in the original answers.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for allowed and excluded processing and storage geographies, license to use and intended data use. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify