Free tool

The 19 questions your CISO should ask any AI vendor

Vantegrate included. Evaluate up to 3 vendors side by side and take away a comparison scorecard with the answers.

Book a demo
Up to 3 vendors. The on-screen result is free and requires no sign-up.
Question

Visible scoring: Yes = 2 · Partial = 1 · No = 0 · No answer = 0 (red flag)

Vantegrate

Reference answer

Category 1: Data residency and ownership
1.Where does the data physically reside, and in which region?
Yes (2)

In the customer's infrastructure: their Salesforce org or their OCI tenancy, in the region the customer defines.

2.Who owns the data, and what happens to it when the contract ends?
Yes (2)

The customer. The data lives in their systems; when the contract ends, it stays where it always was.

3.Is customer data used to train third-party models?
Yes (2)

No.

4.Are there configurable retention and deletion policies?
Yes (2)

Yes, according to the customer's policy.

Subtotal08
Category 2: Encryption and access
5.Is there encryption in transit (TLS 1.2 or higher) and at rest (AES-256)?
Yes (2)

Yes, inherited from the platform (Salesforce or OCI).

6.Does it support multi-factor authentication and SSO (SAML, OAuth 2.0)?
Yes (2)

Yes, with the native mechanisms of the customer's platform.

7.Are permissions granular by user, role and record?
Yes (2)

Yes, with the Salesforce or OCI permission model.

8.Can sensitive data be masked for unauthorized users?
Yes (2)

Yes, configurable by field and by role.

Subtotal08
Category 3: Audit and traceability
9.Is there a complete and unalterable log of access and operations?
Yes (2)

Yes, with the platform's native auditing (for example, Salesforce Shield when enabled).

10.Can you tell who viewed which data and when?
Yes (2)

Yes.

11.Are there alerts for anomalous behavior?
Yes (2)

Yes, configurable at the platform level.

12.Can audit reports be exported for internal or external compliance?
Yes (2)

Yes.

Subtotal08
Category 4: Compliance and certifications
13.What platform does the solution run on, and what certifications does that platform hold?
Yes (2)

100% on Salesforce or on OCI, depending on the customer's stack. The certifications (SOC 2, ISO 27001/27017/27018/27701, PCI DSS, among others) belong to those platforms.

14.Does the vendor distinguish between its own certifications and the certifications of the platform it runs on?
Yes (2)

Yes, and it is Vantegrate's public policy: we do not claim platform certifications as our own. Vantegrate enables, the customer operates and certifies.

15.Does it comply with the local data protection regulations of your jurisdiction?
Yes (2)

Residency and compliance are configured on the customer's platform according to their jurisdiction.

Subtotal06
Category 5: Continuity and exit
16.Is there a documented availability SLA?
Yes (2)

Depending on the contracted plan; infrastructure availability is backed by the platform.

17.Are there automatic backups and a disaster recovery plan?
Yes (2)

Inherited from the platform, plus those specific to each implementation.

18.Is support provided in your language, with defined response times?
Yes (2)

Yes, in Spanish and English, with response times defined by contract.

19.Is there an exit plan with full data export in standard formats?
Yes (2)

Yes. The data already lives in the customer's systems; the export uses the standard tools of their platform.

Subtotal08
Total (0 to 38)
0/ 38 · Red

19 not rated or unanswered

38/ 38 · Green

Live scorecard

Vendor 1

0/ 38

Red

19 question(s) not rated or unanswered

Vantegrate (reference)

38/ 38

Green

Answers published on this page

With the answers you entered, subtotals by category and the "How to read the answers" guide. The on-screen checklist is free and requires no sign-up.

Send this link to whoever signs off on the budget.

About this tool

What the AI vendor security checklist covers

Evaluating an artificial intelligence vendor without a list of questions is signing blind: data security is defined before the contract, not after.

The 19 questions in the checklist

The checklist brings together 19 security questions, covering privacy and compliance, organized by topic: where the data is hosted, who can access it, whether it is used to train models, which certifications back the infrastructure, how incidents are handled and what happens to the information when the contract ends.

Each question is answered as meets, partial or does not meet, and you can evaluate up to 3 vendors side by side, Vantegrate included: the same questions apply to any of them.

What the scorecard is for

The result is a comparison scorecard with subtotals by area, designed to give the security committee or the CISO consistent criteria instead of each vendor's brochures. Vantegrate's security posture is published on the Security page.

The downloadable PDF and CSV keep the answers you entered, ready to attach to a due diligence process.

Frequently asked questions

Frequently asked questions

Why does Vantegrate publish its own answers?

Because transparency is shown, not declared. Use the same 19 questions with any vendor, us included.

What does question 14 mean?

That Salesforce or OCI certifications are not certifications of the vendor that runs on them. Making that distinction speaks to the vendor's honesty.

What does Vantegrate do with my data?

We only use your details to follow up on your report and to contact you if you ask. You can unsubscribe whenever you want.

Want to see these numbers in your real operation?

A 30-minute demo with your case, no commitment. Or message us on WhatsApp and let's talk it through.

Highest score

0 / 38