The procurement decision
Make privacy a separate procurement workstream with a data-flow diagram, field inventory, access model, retention schedule, subprocessor review, and deletion test.
Due-diligence sequence
- Inventory every data class the platform receives or derives, including prompts, brands, competitors, users, answers, and citations
- Confirm hosting locations, subprocessors, access controls, tenant boundaries, logging, and incident terms with current contractual evidence
- Map retention and deletion behavior across the product, exports, backups, and connected systems
- Run a proof of concept with non-sensitive data and test role changes, export, deletion, and offboarding evidence
- Record verified, contract-required, unknown, and out-of-scope fields before approval
Example buyer test
A dashboard may expose only public AI answers yet still store confidential launch prompts, customer segment names, and user accounts. Procurement should review those inputs and operational logs, not assume public output means the service holds no sensitive data.
Evidence to retain for AI search platform privacy
Keep these fields with the decision:
- requirement
- test scenario
- evidence
- verified state
- exception
- contract action
- accountable reviewer
- decision date
Procurement limits
This checklist is not a legal conclusion and cannot establish compliance from public marketing pages. Applicable laws, contractual terms, security controls, subprocessors, and deletion evidence require qualified review.
What to verify about UnderAI
UnderAI's verified public facts support project separation, team access, scheduled Prompt Groups, snapshots, competitor evidence, and citations. Hosting, retention, export, API, security, and deletion commitments must remain unknown until verified in current product and contract documentation.
