FAQ · Frequently asked questions
Vendor security questions, answered from what vendors publish.
Real questions buyers ask when reviewing a SaaS or AI vendor's security. SaaSDossier answers them the way it works everywhere: it records what the vendor publishes, marks each field Documented or Question surfaced, and links the source. That record supports a vendor security questionnaire or DDQ — evidence to map to your own review lines, and the questions that remain for follow-up. It does not complete the questionnaire, make the third-party-risk decision, or approve the vendor. A dossier does not decide whether a vendor is good or bad.
Vendor security questionnaires and DDQs
Reviewed vendor-published sources established the field for the evidence date.
Reviewed vendor-published sources did not establish the field for the evidence date. This does not establish absence of the control.
DATA RETENTION & DELETION
What should buyers ask a SaaS or AI vendor about retention periods for data, logs, prompts, and deletion triggers?
Does a SaaS or AI vendor publish whether Zero Data Retention is available, which endpoints or models are eligible, and how it is enabled?
What should buyers confirm about customer data deletion when a vendor contract ends?
Does a vendor publish how long backups are retained after deletion and whether prompts or embeddings are purged from backups?
AI TRAINING ON CUSTOMER DATA
Does a SaaS or AI vendor train or fine-tune on customer inputs, prompts, or outputs by default?
If a vendor sends data or code to an underlying model provider, what does it publish about whether that provider can train on it?
How can buyers track changes to a vendor's data-use or model-training policy?
SUBPROCESSORS & MODEL-PROVIDER DISCLOSURE
Does a vendor publish which subprocessors can see prompt or API request content and which only see metadata?
Does a vendor publish which LLM or model provider it uses, the model version, and who hosts the model?
If buyers adopt an AI vendor, what should they ask about disclosing that vendor or its AI provider as a subprocessor to their own customers?
What does a vendor publish about subprocessor-change notice periods and objection rights?
ATTESTATIONS & ASSESSMENT ARTIFACTS
What SOC 2 details should a buyer look for in a vendor's published materials?
Does a vendor publish whether external penetration test or audit reports are available, and whether access requires an NDA?
Does an AI vendor publish whether its model or service has been assessed by an external third party?
EVIDENCE ACCESS & QUESTIONNAIRE FRICTION
Will a vendor complete a buyer's security questionnaire, or only provide a SOC 2 report or trust portal?
What source-linked evidence can buyers request behind a vendor's security claim, beyond a policy statement?
Is another party's SOC 2 report, such as a subprocessor or data-center report, enough evidence for the vendor's own security review?
Does a vendor publish whether it charges for security questionnaires or requires an NDA before sharing evidence?
DPA, LEGAL & IP OWNERSHIP
Does a vendor publish a DPA, its key terms, and whether it will execute one with customers?
Does a vendor publish whether it will sign a BAA, support HIPAA-regulated use, and whether that depends on tier or cost?
What does a vendor publish about ownership of customer data and IP rights in AI-generated outputs?
What does a vendor publish about legal holds or compelled retention orders and how those interact with deletion commitments?
BREACH & INCIDENT HISTORY
What does a vendor publish about security incidents or breach-notification history?
Does a vendor publish whether it carries cyber insurance and what the coverage is?
What does an AI vendor publish about detecting and managing incidents affecting models, RAG systems, or agent tooling?
ACCESS CONTROL & PERSONNEL SECURITY
Does a vendor publish who can access customer data and what approval, logging, or support controls govern that access?
Does a vendor publish personnel security controls such as NDAs, background checks, and security-awareness training?
ENCRYPTION, KEYS & TENANT ISOLATION
Does a vendor publish how customer data is separated between tenants and how tenant isolation is enforced?
Does a vendor publish whether vector embeddings of customer data are encrypted and subject to the same retention and deletion rules?
AI-SPECIFIC SECURITY
What does an AI vendor publish about defenses against prompt injection, including indirect prompt injection from retrieved or ingested content?
What does a vendor publish about RAG access controls and defenses against retrieval or corpus poisoning?
Does a vendor publish how its AI service supports traceability or framework mapping such as EU AI Act Article 12, NIST AI RMF, or ISO 42001?
Does a vendor publish whether external LLM traffic is routed through a private API or public endpoint, and whether traffic is isolated?
VENDOR VETTING & REVIEW SCOPE
What does a vendor publish about handling confidential customer data?
How should buyers decide how much vendor security review is proportionate for a lower-risk SaaS tool?
How does a vendor publish its continuous monitoring of third-party or subprocessor controls after onboarding?
Each SaaSDossier release is a dated evidence record. Vendor pages can change after preparation, so each dossier should be read as a snapshot of the vendor-published sources reviewed at the time of preparation. If a buyer identifies a material factual error against a cited source, SaaSDossier will review and correct the record.
- For use within one purchasing organization.
- Unlimited internal users inside that organization.
- Excerpts may be shared with external auditors, vCISOs, counsel, procurement reviewers, or GRC advisors under confidentiality.
- Redistribution, resale, public posting, or use as a competing dataset is not permitted.
