What will a buyer ask about our AI app?
Expect questions on how the product was tested, who can access customer data, where data is hosted, which AI models and providers process it, whether it trains any model, how prompt injection is handled, and whether you have a recent penetration test and a security policy. A test report, a short AI data flow description and honest answers get most small vendors through.
Questions and the evidence that answers them
| Question | Evidence |
|---|---|
| Has the product been independently tested? | Penetration test summary letter with retest |
| Which AI providers process our data? | A list with regions and terms |
| Is our data used to train models? | Provider settings and contract terms |
| How do you prevent prompt injection? | AI security assessment findings and controls |
| How is our data separated from other customers'? | Architecture description and test result |
| Where is data stored? | Hosting regions, including whether in Canada |
| Do you hold SOC 2 or ISO 27001? | Report, certificate, or a plan and timeline |
Prepare before it arrives
Write a one-page security overview and an AI data flow description, have the app and the AI feature tested, and keep a questionnaire answer bank. A trust page that answers the common questions in advance saves repeating them for every buyer.
Be accurate
An inaccurate questionnaire answer becomes a contract representation. "Not yet, planned for Q2" is better than an overstatement.
Questionnaire formats you will meet
Larger buyers send standard questionnaires such as the SIG or the CAIQ, often with an added AI section, or their own spreadsheet of a few dozen to a few hundred questions. Smaller buyers send a short list by email. Either way, many questions repeat. Keep your answers in one document, with the evidence attached to each, and reuse them. Update the bank when your product or providers change.
Where a question does not apply, say why rather than leaving it blank. Where you do not meet a control yet, say what you do instead and when that will change. Buyers expect small vendors to have gaps; they reject vague or inconsistent answers. A trust page that publishes your security overview and subprocessors can answer the common questions before they are asked.
Getting it checked
TrazTech offers AI and LLM security assessments, listed from $4,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Will they reject an AI-built product?
Rarely for that reason alone. They reject products that cannot show testing and data separation.
Is a SOC 2 report required?
Larger buyers often want one. A recent pentest can carry a first deal.