Security Questions
Does the vendor offer zero-history architecture? What PII redaction capabilities exist? How are guardrails implemented? What encryption standards are used? Can you deploy on-premises?
Compliance Questions
Is the vendor SOC 2 certified? Do they offer BAAs for HIPAA? How do they handle GDPR cross-border transfers? What audit log exports are available? Can you configure data sovereignty controls?
Cost Questions
What's the pricing model? Are there department-level budget controls? How is cost normalized across models? What happens when budgets are exhausted? Is there transparent per-token pricing?
Capability Questions
How many AI models are available? What integration options exist? Is there SSO support? How are custom guardrails configured? What deployment options are offered (cloud, on-prem, hybrid)?
.png)