Generator
AI Vendor Security Questionnaire
Generic security questionnaires miss what is specific about an AI vendor: what happens to your content, which model actually runs, and whether they can tell you when that changes. This generates the questions, and what a bad answer looks like.
- AI specificNot a generic SaaS form
- Flags bad answersSo you know what to push on
- Sized to riskNot thirty questions for a pilot
Work it out
Your numbers
Your system prompt
The value is as much in the answers you refuse to accept as in the questions. Any answer that cannot be checked is not an answer.
What the numbers mean
Ask who runs inference, by name
“Industry leading models” tells you nothing about where your visitors' questions go. The provider and the processing country are the two facts everything else rests on.
“We do not sell your data” answers a different question
Training is not selling. A vendor can honestly say they never sell data while using your conversations to improve a shared model. Ask about training explicitly.
Silent model changes are the under-asked risk
If the vendor swaps provider without telling you, your processing changed and your DPA may no longer describe reality. Ask for the notification commitment in writing.
A vendor who says “not yet” is often the safer one
Honest gaps with dates are easier to manage than a form with yes in every box. Treat a perfect score as a reason to check harder, not to relax.
Questions
Yes, which is why the list is sized to risk. A pilot on public marketing pages generates six questions, not thirty.
Note it and decide whether the gap matters at your risk level. An early-stage vendor that says so plainly is different from an established one that dodges.
The security page and the security questionnaire page state what is settled and what is not, including the parts that are not built yet.
Want this run against your actual site?
Tell us the page your assistant lives on and the questions you care about. A person runs them and sends back the raw answers.