Risk & safety
The Vendor Evaluation Card
A DIY evidence pack on whether a tool is safe for your business data.
1
Training
Does the policy explicitly say they do not train on your data?
2
Data retention
How long do they keep your inputs, and can you delete them?
3
Security
Encryption, access controls, and where the data is hosted.
4
Reference
Can they point to real customers running it the way you would?
The rule
If the evidence is not public, assume the protection does not exist.
When to use Before putting business data into a tool you cannot audit or negotiate with.
Read it in The AI Pilot Handbook →