AI Support

The Security and Data Questions to Ask Any AI Support Vendor

Short answer

Ask five things: whether your conversations train third-party models, where data is stored and whether it can stay in a region, what the retention and deletion terms are, who the sub-processors are, and what happens to your data at termination. Get all five in writing.

Key takeaways

  • Model training on your conversations is the question buyers most often forget.
  • Sub-processor lists change, so ask how you are notified.
  • Termination data handling is easier to negotiate before signing.
  • Support transcripts contain more personal data than teams assume.

Support transcripts contain more sensitive information than most teams assume. Customers explaining a problem routinely volunteer health details, financial circumstances, and personal situations that never appear in any structured field.

Putting that through an AI system is a reasonable thing to do and it deserves five specific questions. Ask them of every vendor, including us, and get written answers.

1. Are our conversations used to train models?

The question people most often forget to ask, and the one with the longest consequences.

Ask specifically:

  • Are our conversations used to train the vendor’s own models?
  • Are they passed to a third-party model provider, and if so, under what terms?
  • Is there a contractual commitment, or just a policy that can change?

A policy page is not a contract. If this matters, it belongs in the agreement.

For transparency: Fidiora does not use customer conversations or customer data to train third-party models.

2. Where is the data stored?

Two parts: where it rests, and where it is processed.

A vendor may store data in your region and process it elsewhere, which is a meaningfully different answer for some regulatory regimes. Ask about both explicitly rather than accepting a single answer about hosting.

If you have a residency requirement, ask whether it can be guaranteed for your account specifically rather than being a general capability.

3. What are the retention and deletion terms?

  • How long are conversations retained by default?
  • Can we set a shorter retention period?
  • How do we delete a specific customer’s data on request?
  • How long does deletion take to propagate, including backups?

That last one matters for subject access and deletion requests, which carry legal timelines in several jurisdictions. A vendor who cannot answer it is a vendor who will make you miss one.

4. Who are the sub-processors?

Every AI vendor uses others: a model provider, cloud infrastructure, possibly analytics or monitoring services.

Ask for the current list and, more importantly, how you are notified when it changes. A sub-processor added quietly is a change to your data flow that you agreed to without knowing.

5. What happens at termination?

Easier to negotiate before signing than after, by a wide margin.

  • How do we export our data, in what format?
  • How long do we have after termination?
  • When does the vendor delete their copy, and is that confirmed?
  • Do we retain access to historical conversations, and for how long?

A vendor unwilling to be specific here is one whose data you may struggle to retrieve at exactly the moment the relationship has soured.

The operational questions too

Beyond data handling, three practical ones:

What does the AI have access to? If it can read customer records or take actions, what is the permission scope, and can it be narrowed? Least privilege applies here exactly as it does anywhere else.

Is every action logged? For any system that changes account state, a complete audit trail is not optional. Ask whether you can see it and export it.

How are prompt injection and manipulation handled? A customer can attempt to instruct the system through a message. Ask what prevents that from changing its behaviour or extracting information about other customers.

The self-hosting question

Teams with strict requirements frequently assume self-hosting is the only route. It is one route and it has real costs: hosting, upgrades, security patching, backups, and on-call responsibility for a customer-facing system.

Before committing to that, ask commercial vendors the five questions above. Several can meet residency and model-training requirements contractually, and a contractual commitment from a vendor who patches their own systems is often a better security position than a self-hosted deployment nobody has time to update.

The honest test: if you self-host, who patches it, and how quickly? If the answer is uncertain, the commercial option may be safer as well as cheaper.

Documenting your position

Whatever you decide, write it down somewhere customers and prospects can read it.

Enterprise buyers will ask these questions during procurement. A published document answering them once turns a recurring deal-slowing conversation into a link, and it signals a level of seriousness that a case-by-case answer does not.

We publish ours at fidiora.com/security for the same reason.

The one-line summary

Get five answers in writing: model training, residency, retention and deletion, sub-processors, and termination. Then ask who patches whatever you choose. Those six things cover most of the practical risk in putting support conversations through an AI system.

Frequently asked questions

Is my customer data used to train AI models?
That depends entirely on the vendor contract and it is a question you should get answered in writing. Fidiora does not use customer conversations or customer data to train third-party models.
What data lives in support conversations?
More than teams assume. Names, contact details, account identifiers, order contents, payment references, and frequently health, financial, or personal circumstances that customers volunteer while explaining a problem.
Should I self-host to keep data control?
Only if residency or control is a genuine regulatory or contractual requirement. Ask commercial vendors directly about residency and model training first, because self-hosting carries real operating and security cost.
What should I ask about data at termination?
How you export it, in what format, how long you have, and when the vendor deletes their copy. These are far easier to negotiate before signing than after.
ai securitydata privacyvendor securityai support

Resolve, don't deflect.

See Fidiora resolve a ticket, capture a lead, and keep the bill predictable.

See Pricing