Data residency and model hosting: what to put in your security questionnaire

Mar 23, 20269 min read
Security and compliance themed abstract visual

Why this matters

Security reviews often fail because teams ask generic cloud questions instead of AI-specific questions. Your questionnaire should separate app infrastructure controls from model execution controls.

What to ask vendors

Ask where prompts, transcripts, and embeddings are processed and stored, who can access them, and what retention policy applies by default.

Require clear answers on regional processing, private model hosting options, and deletion SLAs for customer data and derived artifacts.