AI security / AI buyer due diligence pack

AI security questionnaire answers your buyer will accept.

An enterprise customer added AI questions and the deal stopped. We write the answers and build the evidence.

The trigger

The questions procurement now attaches to every AI feature.

The AI module is no longer a paragraph in a vendor questionnaire. The Cloud Security Alliance published CSA AI Controls Matrix v1.1 on 22 June 2026, with 247 control objectives across 18 domains and a 320-question AI questionnaire beside it. Your buyer is increasingly sending rows from that, not prose.

Our position

Buyers stopped accepting prose.

Buyers stopped accepting prose because the follow-up is a live session. An answer you cannot show in a console is an answer that fails on the call. So every answer in the pack cites the evidence behind it, and the evidence is built first.

What we build

The evidence first, then the answers.

  • Every model, provider and region in the request path.
  • The subprocessor list, including anything a tool calls.
  • Retention and training settings read in the provider console.
  • One real request traced from prompt to log to deletion.
  • The human approval boundary for every action that writes.
  • The prompt-injection defences you have, and the ones you do not.
Five answers that stop a deal

What survives the follow-up call.

The left column is the common answer. The right column is what the security team asks for next.
The answer that failsWhat it has to show
We do not train on customer data.Named provider, the console setting that proves it, and the date read.
Data stays in Australia.The region per model call, plus the hop that leaves it if one does.
A human reviews every AI action.The actions that write, and the service that enforces the approval.
We have guardrails against prompt injection.The specific defence per entry point, and the ones you have not built.
Our AI is SOC 2 covered.Whether the AI path was in the audited scope, in writing.
What you receive

A pack the next deal reuses.

  • AI Architecture Summary a security team reads without a call.
  • Model and subprocessor inventory with owner and region.
  • Answered questionnaire with an evidence reference per row.
  • Draft public AI transparency section for your own site.

The pack is yours and it is written to be reused, so the second questionnaire starts from a document rather than from nothing. Where the answer depends on what an agent can reach, the agent security review produces that evidence.

Scope tiers

Priced by the number of models in the request path.

Elapsed days from the point console access is ready.
ScopeTypical elapsed timeReuse
One AI feature, one providerSeven daysReusable for the next deal
Multiple features or agents with toolsTen to fourteen daysReusable for the next deal
Multi-tenant platform with regulated dataQuoted after the model inventoryAgreed in writing first
Failure modes

Why the same questionnaire hurts twice.

  • The answer is written once and never reused.
  • Nobody internally owns the model inventory.
  • The contract has no model-change notification clause.
  • Retention is described from the brochure, not the console.

If the buyer wants an attestation over the whole system rather than the AI path, that is SOC 2 readiness and it runs on a different timeline.

Limits matter

What this pack excludes

  • We do not answer a question untruthfully to unblock a deal.
  • Not SOC 2 or ISO 27001 readiness. Those are separate.
  • Not an audit, an attestation or a certification.
  • Not legal advice. Contract drafts go to your lawyer.
  • We do not join the buyer call as your employee.
Questions before you book

Practical answers.

Do we need SOC 2 as well?

Often, but not for the same reason and not on the same timeline. This pack answers the AI questions attached to the questionnaire. If the buyer requires an attestation over the whole system, that is SOC 2 readiness and it is a separate engagement.

Can you join the buyer security call?

We can attend as your named external reviewer and answer the technical questions we built the evidence for. We will not present as your employee, and we will not answer a question the evidence does not support.

How fast can this move if the deal closes this month?

One feature with one provider is seven days once access is ready. The slow part is never the writing. It is getting console access and a straight answer about which model the request actually hits.

What if our answer is genuinely bad?

You get it in writing, with the smallest change that makes it defensible and an estimate of the effort. A bad answer disclosed early loses a week. The same answer discovered on the follow-up call loses the deal.

Do we need a compliance platform first?

No. A platform stores evidence you already have. The work here is producing the evidence, and a subscription does not do that part.

Different trigger, different starting point. AI agent security review and AI coding agent control baseline answer the other two questions, and all AI security services routes on the event. For adversarial testing of the feature itself, AI application security testing.

Framework and advisory versions above were read from the primary source on 17 September 2026.

Let’s scope it

Send us the questionnaire.

Paste the AI section and name the deadline. We will say what the evidence needs before quoting.

Request a quote

Last reviewed: