The SMB Guide to Vetting AI Vendors for Data Security: What to Ask, What to Require, and What to Walk Away From

The SMB Guide to Vetting AI Vendors for Data Security: What to Ask, What to Require, and What to Walk Away From

Most small businesses evaluate AI tools the same way they evaluate productivity software: they look at features, read a few reviews, check the pricing page, and sign up for a trial. If the tool does what it claims and the price fits the budget, they subscribe. The data security implications of that decision — what the vendor does with the data submitted through the platform, what protections exist against unauthorized access, what happens to business data if the vendor is breached — rarely receive the scrutiny they deserve.

This approach was understandable when AI tools were processing low-stakes content. It is not understandable when AI tools are processing client financial records, protected health information, legal documents, employee data, or proprietary business information — as they routinely are in small business deployments today. The AI vendor you choose when you deploy an AI tool for client proposal drafting or document analysis is not just a software vendor. They are a data processor with access to some of your most sensitive business information, and the security practices governing their platform are directly relevant to your business’s regulatory compliance, cyber insurance coverage, and professional liability exposure.

This guide provides a practical framework for AI data security for SMBs at the vendor evaluation stage — the questions to ask before signing, the contractual protections to require, and the red flags that should send you looking for a different vendor regardless of how impressive the feature set is.

Phase One: Understanding What the Vendor Actually Does With Your Data

The first and most important set of questions in any AI vendor security evaluation focuses on data handling: specifically, what the vendor does with the data you submit through their platform, how long they retain it, who has access to it, and whether it is used for any purpose beyond delivering the service you contracted for.

The single most consequential question is whether the vendor uses customer data to train or improve their AI models. Many consumer AI platforms — including widely used tools that small businesses have adopted for work purposes — include terms that grant the vendor broad rights to use submitted data for model training, product improvement, and research purposes. For businesses whose data includes client information, the implications of this are serious: submitting a client’s financial records to an AI tool that retains and may use that data for training purposes is sharing that client’s information with a third party in a way that almost certainly was not disclosed to or consented to by the client.

The answer you need: a clear, contractual commitment that the vendor will not use your data for model training, product improvement, or any purpose beyond delivering the contracted service. This commitment should appear in the vendor’s terms of service or data processing agreement — not just in a sales representative’s verbal assurance. If the vendor cannot provide this commitment in writing, or if their standard terms reserve training rights that cannot be waived for SMB accounts, that vendor is not appropriate for use with sensitive business data regardless of their other capabilities.

The second critical data handling question is retention: how long does the vendor retain data submitted through the platform, and what is the process for deletion? Standard consumer AI platforms often retain interaction data — including the text and documents submitted in queries — for extended periods, sometimes indefinitely, under terms that allow use for unspecified internal purposes. Enterprise AI platforms typically offer more defined retention terms, often configurable by the customer, with a clear deletion process upon contract termination.

For regulated businesses, retention terms must be evaluated against the applicable regulatory framework. HIPAA, for example, requires that Business Associates (including AI vendors processing PHI) retain protected health information only as long as necessary for the purposes of the service and dispose of it appropriately thereafter. A vendor whose retention terms are inconsistent with HIPAA’s disposal requirements is not a viable option for healthcare AI deployments, regardless of other capabilities.

The third data handling question addresses access: who within the vendor organization has access to the data submitted through the platform, under what circumstances, and with what controls? Most reputable enterprise AI vendors maintain strict internal access controls that limit employee access to customer data to defined operational purposes — support, security investigation, required legal compliance — with audit logging of all access events. Vendors who cannot describe their internal data access controls in specific terms, or who maintain broad employee access to customer data without defined purpose limitations, present elevated risk regardless of their technical security credentials.

Phase Two: Technical Security — What to Verify and How

Beyond data handling practices, AI vendor security evaluation requires assessment of the technical security controls that protect data in transit, at rest, and during processing. For SMBs without dedicated security staff, this evaluation can feel intimidating — but the key questions are not technically complex, and reputable vendors answer them readily with documentation that confirms their security posture.

Encryption in transit and at rest is the baseline technical security requirement for any AI vendor processing sensitive business data. Data submitted to an AI platform should be encrypted in transit using current TLS standards, and data stored by the vendor should be encrypted at rest. This is a minimum standard, not a differentiator — any enterprise-grade AI vendor will meet it — but it is worth confirming explicitly, as some lower-tier platforms do not maintain current encryption standards throughout their data pipeline.

Security certifications provide a structured way for SMBs to evaluate AI vendor security posture without conducting a full technical assessment. The most relevant certifications for AI vendor evaluation are SOC 2 Type II — an audit of the vendor’s security controls over a defined period that demonstrates sustained security practice, not just point-in-time compliance — and ISO 27001, an international information security management standard. Vendors with current SOC 2 Type II reports can provide that report upon request, and reviewing it (or having a security-knowledgeable advisor review it) reveals specific control areas and any noted exceptions that the audit identified.

Vendors who cannot provide current SOC 2 Type II documentation — or who provide only a SOC 2 Type I report, which is a point-in-time assessment rather than a sustained-period audit — have a less mature security posture than those with current Type II certification. For SMBs making decisions about which AI vendors to trust with sensitive data, this certification status is a meaningful differentiator.

Penetration testing and vulnerability management practices are the next layer of technical security evaluation. Reputable AI vendors conduct regular third-party penetration testing of their platforms and maintain documented vulnerability management processes. Asking a vendor when their most recent penetration test was conducted, whether findings were remediated, and what their vulnerability disclosure process looks like provides insight into the maturity of their security operations that certification documentation alone does not capture.

Breach history and incident response capability round out the technical security evaluation. A vendor who has experienced security incidents and handled them well — with prompt detection, rapid response, transparent customer notification, and documented root cause analysis and remediation — may present a more trustworthy security posture than a vendor with no disclosed breach history but no evident incident response capability. Asking specifically what the vendor’s breach notification process is for customer data incidents, what the notification timeline is, and how previous incidents have been handled provides a realistic picture of what to expect if something goes wrong.

According to CISA’s cybersecurity resources for small and medium businesses, vendor security assessment is consistently identified as one of the highest-leverage security investments available to small businesses — because the security failures that most frequently affect SMBs originate not from direct attacks on the SMB but from breaches of the vendors and service providers the SMB has shared data with. Assessing AI vendor security before deploying is the most cost-effective point in the relationship to identify and address vendor risk.

Phase Three: Contractual Protections — What to Require Before You Sign

Even the most technically secure AI vendor with the strongest data handling policies presents risk to an SMB client if the contractual framework governing the relationship doesn’t include the specific protections the business needs. The gap between what a vendor’s marketing materials say and what their contracts actually obligate them to do can be significant, and the contract is what governs in the event of a dispute or incident — not the sales deck or the website FAQ.

The data processing agreement or DPA is the core contractual instrument for AI vendor data security. A DPA specifies what data the vendor is authorized to process on the business’s behalf, for what purposes, under what security standards, and with what obligations in the event of a breach or unauthorized access. For regulated businesses, the DPA must satisfy the requirements of the applicable regulatory framework: the HIPAA Business Associate Agreement for healthcare businesses, the data processing agreement requirements under GDPR for businesses with European clients, and equivalent instruments for other applicable frameworks.

SMBs in regulated industries should never assume that a vendor’s standard DPA satisfies their specific regulatory requirements. Standard DPAs are written to satisfy the broadest possible client base and may not include the specific provisions required by HIPAA, the FTC Safeguards Rule, or applicable state privacy laws. Reviewing the standard DPA against your specific regulatory requirements — or having legal counsel do so — before signing is the only way to confirm that the contractual protections in place actually satisfy your compliance obligations.

Breach notification provisions specify the timeline and process for the vendor to notify the business in the event of a security incident affecting the business’s data. Standard terms often include notification timelines of 72 hours or longer — timelines that may be insufficient for regulated businesses with faster notification obligations to their own regulators or clients. Negotiating notification timelines that meet your specific obligations — 24-hour notification for businesses with rapid regulatory reporting requirements, for example — is a reasonable ask for businesses with defined compliance timelines.

Audit rights provisions give the business the contractual right to request information about the vendor’s security controls and compliance status — and in some cases the right to conduct security assessments of the vendor’s platform. For regulated businesses whose own compliance programs require vendor oversight, audit rights provisions are not optional — they are the mechanism through which the business demonstrates that it is exercising the vendor oversight that regulators expect.

Subprocessor transparency provisions require the vendor to disclose any subcontractors or third-party services that will have access to the business’s data, and to notify the business of any changes to its subprocessor roster. AI platforms routinely use third-party infrastructure — cloud hosting, data processing, API services — that creates additional access points for business data. Understanding the full chain of data handling relationships is essential for businesses whose compliance obligations extend to all parties with access to regulated data.

According to the Federal Trade Commission’s data security guidance, businesses are responsible for ensuring that the vendors they share data with maintain reasonable security practices — and the contractual frameworks governing those relationships are the primary mechanism through which that responsibility is exercised. An SMB that signs an AI vendor contract without reviewing its DPA, breach notification terms, and data handling provisions is not exercising the vendor oversight that the FTC’s reasonable security standard requires, regardless of how strong the vendor’s own security posture is.

Red Flags That Should End the Evaluation

Beyond the specific questions and requirements above, certain vendor behaviors during the evaluation process are red flags serious enough to warrant ending the evaluation regardless of the tool’s capabilities or pricing.

A vendor who cannot or will not provide a Data Processing Agreement is not suitable for use with sensitive business data. DPAs are standard practice for enterprise AI platforms — their absence signals either legal immaturity or deliberate avoidance of contractual data protection obligations. Neither is acceptable for a vendor processing your clients’ information.

A vendor whose standard terms explicitly reserve the right to use customer data for model training and who cannot offer a waiver of those terms for business accounts is not suitable for processing client or regulated data. The revenue model of some AI platforms depends on data acquired from free or low-cost business accounts. Businesses providing client data to fund that model are exposing their clients to uses of their information that were never disclosed or consented to.

A vendor who cannot provide current SOC 2 Type II documentation upon request, who deflects technical security questions with marketing language rather than specific answers, or who has no documented breach notification process is operating below the security maturity threshold appropriate for a data processor handling sensitive business information.

A vendor whose security team cannot be reached through a defined contact channel — who routes all security questions through sales or general support rather than a designated security contact — is not organized for the kind of responsive security relationship that managing AI data risk requires.

The investment of time required to conduct a thorough AI vendor security evaluation — reviewing the DPA, asking the technical security questions, confirming certification status — is measured in hours. The cost of deploying an inadequately vetted AI vendor with sensitive business data and discovering the gap when an incident occurs is measured in regulatory penalties, client relationship damage, and insurance complications that dwarf any efficiency gain the tool provided. The evaluation is not optional; it is the most important security decision in the AI procurement process.

About the author