Read the first three questions below. Get the complete guide — all 12 questions with a good answer and a warning sign for each, plus the printable comparison checklist.
Question 01
Where exactly does inference run?
Why it matters
This is the founding question. Everything else follows from it: applicable jurisdiction, legal exposure, and your ability to document your compliance.
A good answer
A precise, verifiable location — "on the server installed on your premises," or "in this data centre, at this address, operated by this company." The vendor should be able to show you where.
Warning sign
"In the cloud," "on secure servers," "at our infrastructure partner" with no further detail. Vagueness isn't commercial discretion, it's the absence of an answer.
Question 02
Is our data used to train a model?
Why it matters
If your documents are absorbed into a model, you lose all control over where they end up and you can no longer withdraw them.
A good answer
A clear no, together with an explanation of the architecture used instead — typically RAG. The vendor should also address the third-party providers it relies on.
Warning sign
"Your data is anonymized before training," or an answer covering only the vendor without addressing the third-party models it calls.
Question 03
Does every answer cite its source?
Why it matters
Without citations you can neither verify nor defend an answer. In front of a client, a professional order or a court, "the tool told me" is not a defensible position.
A good answer
Yes, with the file, the section and the version. Ask for a live demonstration rather than an assurance.
Warning sign
Vague citations at document level rather than passage level. Or an answer along the lines of "the model is very reliable" — which sidesteps the question.