AI can be useful without becoming a blind data transfer. Approve a tool only after its data flow, retention, training, access, deletion, and answer-review controls fit the sensitivity of your evidence.
Ask these questions before uploading
| Area | Question to ask | Evidence to request |
|---|---|---|
| Data flow | Which companies, regions, models, and services receive the file or extracted text? | Current architecture, subprocessors, and data-flow description |
| Training | Can prompts, documents, answers, metadata, or feedback train or improve any model? | Contract term and product privacy statement |
| Retention | What is stored, for how long, and in which backups or logs? | Retention schedule and deletion process |
| Isolation | Can one customer's evidence affect another customer's retrieval or output? | Tenant-isolation and access-control description |
| Accuracy | Can reviewers see the exact source and mark unsupported answers? | Live review workflow and export record |
| Incidents | How will you learn about unauthorized access or disclosure? | Incident notice term and response process |
Run the review in five steps
Classify what you plan to upload
Questionnaires may reveal architecture, controls, gaps, customer names, contract terms, and audit details. Remove material the tool does not need.
Draw the real data path
Include the application vendor, model provider, storage, logs, support tools, subprocessors, and backup systems. “Encrypted” does not answer where data goes.
Read training and retention terms separately
A promise not to train does not mean no retention. A short retention period does not explain support access, backups, or feedback use.
Test the review workflow
Use synthetic evidence. Confirm that the tool shows sources, preserves unknowns, handles conflict, and requires human approval before submission.
Record the approved use case
State which data may be uploaded, who may use the tool, what review is required, and which cases remain prohibited.
Classify each vendor claim
Use Supported when a current contract or technical source proves the claim. Use Needs review when scope or implementation is unclear. Use Unknown when the vendor has not supplied evidence.
A safe synthetic evaluation
No customer data
Create a fictional policy with two supported controls, one partial control, and one absent certification. Upload it with a synthetic questionnaire.
A safe test checks whether the tool cites the two supported answers, qualifies the partial one, and leaves the absent certification Unknown. It also checks deletion and whether any other account can retrieve the content.
Common mistakes
- Criticizing or approving AI as one category instead of reviewing the implementation.
- Reading only the model provider's policy and ignoring the application vendor.
- Assuming “not used for training” means deleted immediately.
- Testing with live customer documents before the privacy review is complete.
- Accepting answers without citations or a visible unknown state.
How SaneCite handles this
SaneCite says it processes approved evidence on Cloudflare infrastructure, does not send documents to OpenAI, Anthropic, or Google, and does not use customer data to train a model. It shows citations for supported answers and flags unsupported questions for human review. Confirm current terms on its privacy and trust pages before your own approval.
Questions people ask
- Is all security questionnaire AI unsafe?
- No. Risk depends on the implementation, contracts, data flow, access, retention, and review controls.
- Is a zero-retention model enough?
- It helps, but you still need to review the application layer, logs, storage, subprocessors, support access, and output controls.
- Should I upload a SOC 2 report?
- Only after checking its disclosure terms, your policy, and the vendor's controls. A synthetic test should come first.
Primary sources
- NIST AI Risk Management Framework (accessed July 26, 2026).
- NIST AI 600-1, Generative AI Profile (accessed July 26, 2026).
- OWASP LLM02:2025, Sensitive Information Disclosure (accessed July 26, 2026).
- FTC, Protecting Personal Information: A Guide for Business (accessed July 26, 2026).
Published July 26, 2026. No material revisions yet.
Start with a synthetic questionnaire.
Review sources, gaps, and the data path before using live evidence.