Architecture and boundaries
- Describe the service architecture and trust boundaries relevant to customer data.
- Identify material hosting, model, integration, and subprocessor dependencies.
- Explain how customer environments and data are logically separated.
Identity and access
- Describe administrative access controls, authentication, authorization, and review.
- Explain how privileged actions are logged and monitored.
- Describe employee access approval and removal practices.
Data protection
- Describe encryption for data in transit and at rest.
- Explain retention, deletion, backup, and restoration behavior.
- State whether customer data is used to train or improve models and what controls apply.
Secure development
- Describe code review, testing, dependency management, and vulnerability handling.
- Explain how production changes are approved and monitored.
- Describe relevant security testing and the scope and date of available evidence.
Incidents and resilience
- Describe detection, response, customer notification, and lessons-learned practices.
- Explain service continuity assumptions and recovery objectives relevant to the use case.
- Identify customer controls or integrations needed for safe operation.
AI-specific controls
- Describe controls for prompt injection, unsafe tool use, data leakage, and harmful output.
- Explain evaluation methods and known limits for the intended use.
- Describe model or system changes that are communicated to customers.
Evidence note
Request evidence proportionate to the use case. A policy, report, test result, or certification has a defined scope and date; it should not be interpreted as a blanket security assurance.