The Impossible Answer · Decision note 03

How to answer “no external AI processing”

Illustrative situation · Not a customer case
The buyer’s question

Do you guarantee that no customer information is processed by external AI systems?

“Not used for training” does not mean “not processed externally.” First define external and customer information, then trace every enabled path. If a relevant external path is unresolved, do not provide a blanket No-external-processing assurance.

A response to adapt

For [named service, deployment, features and contract scope], [verified statement about whether customer information is processed by an external AI service]. In this response, external means [agreed boundary: outside the device, customer environment, our organization or named hosting provider], and customer information includes [agreed data categories]. For each permitted AI processing path, [approved inventory reference] identifies the operator, purpose, data categories, processing location, retention and applicable training-use terms. [Feature] is [verified enabled/disabled state and enforcement], subject to [documented conditions]. This statement does not cover [explicit exclusions]. We cannot provide a broader assurance until [unresolved path or definition] is verified and approved by [owner]. Please confirm whether this scope addresses requirement [ID] through [authorized clarification channel].

Replace every bracketed field with verified facts. Remove any optional sentence you cannot substantiate. Do not submit this wording unchanged.

The five-path data boundary check

Build one short evidence row for each path: operator, data, purpose, location, retention and approval. A missing row is an unresolved question—not evidence that no processing occurs.

Inference
Identify the actual endpoint and operator for each enabled AI feature. Separate a customer-hosted model from a remotely operated model, even when both use the same model weights.
Retrieval and preparation
Check document parsing, search, embeddings and fetched source passages. A source file staying in its original store does not establish that its retrieved content remains inside the same boundary.
Safety and observability
Review content moderation, abuse detection, request traces and error reporting. Check the approved configuration and applicable terms; do not infer zero retention from stateless inference.
Optional and fallback paths
Verify connectors, feature flags, regional failover and secondary providers. A disabled default is not enough if another role can enable an unapproved path without the stated controls.
Human and support workflows
Establish whether support or staff can copy customer content into external tools, and the actual restrictions. Distinguish documented policy, technical enforcement and evidence of operation.

What makes the wording defensible

Distinguish processing from training, storage and human access. Scope the answer to the real data path, not the model name or a reassuring slogan.

  • Resolve the word “external” before choosing Yes or No

    The buyer may mean outside its network, outside the supplier, outside an approved hosting provider or outside a jurisdiction. Those are not interchangeable. Establish the boundary and response polarity: No to “do you send data?” is different from No to “can you guarantee you do not?”. Request clarification if the required field would conceal that distinction.

  • Separate four questions that sales copy merges

    Determine whether information is processed, retained, used for training and accessible to people. A policy excluding model training answers only one of those questions. Encryption, private networking and a model's brand also do not establish who operates the inference service or where the data is processed.

  • Cover ordinary use and exception paths

    Trace prompts, retrieved passages, attachments, embeddings, outputs and logs. Review optional assistants, integrations, fallbacks, support investigations and employee tools handling customer content. Scope the answer to what the contract actually asks; do not extend a verified product path into an unsupported company-wide claim.

The evidence to obtain

  • A deployment-specific data flow

    Obtain the reviewed diagram and endpoint inventory for the offered environment. Attach evidence of feature states, connector permissions and fallback configuration. Record the version and date so a later deployment change cannot silently inherit the answer.

  • Applicable provider and processor terms

    Match the provider, service, feature and deployment type to its current terms, subprocessor information and contractual arrangements. Microsoft Foundry documentation, for example, distinguishes inference, storage and deployment-dependent processing location; it is not a promise about every Azure feature or any REQVERA implementation.

  • Verification and accountable approval

    Ask the security owner for an authorized configuration or network-path check where appropriate. Logs alone are not universal proof of absence. Privacy and legal reviewers confirm whether the documented path meets this buyer's restriction and disclosure requirements.

The decision to approve

Decision owners
Security or architecture owns the data-flow facts. Privacy and legal approve the scope and required disclosures; the Bid Manager ensures the questionnaire and contractual answer say the same thing.
Proceed
Give a scoped assurance only when every in-scope path is verified, its conditions remain true in the offered configuration and the buyer accepts the defined boundary.
Do not proceed
Do not claim no external processing because training is disabled or the model is described as private. If external processing conflicts with a mandatory condition, record the gap; a polished privacy paragraph does not cure it.
Escalate
Clarify whether the restriction concerns inference, model training, storage, support access, subprocessors or processing location. Resolve unknown paths before signing; do not substitute an assumed buyer intent.

Keep the decision in the final files

Keep the approved data-flow version, feature conditions and disclosed exceptions connected to the final answer. Recheck affected responses after a connector, provider or deployment changes. REQVERA's final-control role does not itself establish the architecture or certify a no-external-processing guarantee.

See the authentic final-control workflow

Scope & primary references

Illustrative questionnaire wording, not a customer incident. General supplier-response practice, not a determination of lawful processing. Provider examples apply only to their documented service and configuration; no REQVERA data-processing capability is inferred from them.