How to answer “no external AI processing”
The buyer’s questionDo you guarantee that no customer information is processed by external AI systems?
“Not used for training” does not mean “not processed externally.” First define external and customer information, then trace every enabled path. If a relevant external path is unresolved, do not provide a blanket No-external-processing assurance.
A response to adapt
For [named service, deployment, features and contract scope], [verified statement about whether customer information is processed by an external AI service]. In this response, external means [agreed boundary: outside the device, customer environment, our organization or named hosting provider], and customer information includes [agreed data categories]. For each permitted AI processing path, [approved inventory reference] identifies the operator, purpose, data categories, processing location, retention and applicable training-use terms. [Feature] is [verified enabled/disabled state and enforcement], subject to [documented conditions]. This statement does not cover [explicit exclusions]. We cannot provide a broader assurance until [unresolved path or definition] is verified and approved by [owner]. Please confirm whether this scope addresses requirement [ID] through [authorized clarification channel].
Replace every bracketed field with verified facts. Remove any optional sentence you cannot substantiate. Do not submit this wording unchanged.
The five-path data boundary check
Build one short evidence row for each path: operator, data, purpose, location, retention and approval. A missing row is an unresolved question—not evidence that no processing occurs.
- Inference
- Identify the actual endpoint and operator for each enabled AI feature. Separate a customer-hosted model from a remotely operated model, even when both use the same model weights.
- Retrieval and preparation
- Check document parsing, search, embeddings and fetched source passages. A source file staying in its original store does not establish that its retrieved content remains inside the same boundary.
- Safety and observability
- Review content moderation, abuse detection, request traces and error reporting. Check the approved configuration and applicable terms; do not infer zero retention from stateless inference.
- Optional and fallback paths
- Verify connectors, feature flags, regional failover and secondary providers. A disabled default is not enough if another role can enable an unapproved path without the stated controls.
- Human and support workflows
- Establish whether support or staff can copy customer content into external tools, and the actual restrictions. Distinguish documented policy, technical enforcement and evidence of operation.
What makes the wording defensible
Distinguish processing from training, storage and human access. Scope the answer to the real data path, not the model name or a reassuring slogan.
Resolve the word “external” before choosing Yes or No
The buyer may mean outside its network, outside the supplier, outside an approved hosting provider or outside a jurisdiction. Those are not interchangeable. Establish the boundary and response polarity: No to “do you send data?” is different from No to “can you guarantee you do not?”. Request clarification if the required field would conceal that distinction.
Separate four questions that sales copy merges
Determine whether information is processed, retained, used for training and accessible to people. A policy excluding model training answers only one of those questions. Encryption, private networking and a model's brand also do not establish who operates the inference service or where the data is processed.
Cover ordinary use and exception paths
Trace prompts, retrieved passages, attachments, embeddings, outputs and logs. Review optional assistants, integrations, fallbacks, support investigations and employee tools handling customer content. Scope the answer to what the contract actually asks; do not extend a verified product path into an unsupported company-wide claim.
The evidence to obtain
A deployment-specific data flow
Obtain the reviewed diagram and endpoint inventory for the offered environment. Attach evidence of feature states, connector permissions and fallback configuration. Record the version and date so a later deployment change cannot silently inherit the answer.
Applicable provider and processor terms
Match the provider, service, feature and deployment type to its current terms, subprocessor information and contractual arrangements. Microsoft Foundry documentation, for example, distinguishes inference, storage and deployment-dependent processing location; it is not a promise about every Azure feature or any REQVERA implementation.
Verification and accountable approval
Ask the security owner for an authorized configuration or network-path check where appropriate. Logs alone are not universal proof of absence. Privacy and legal reviewers confirm whether the documented path meets this buyer's restriction and disclosure requirements.
The decision to approve
- Decision owners
- Security or architecture owns the data-flow facts. Privacy and legal approve the scope and required disclosures; the Bid Manager ensures the questionnaire and contractual answer say the same thing.
- Proceed
- Give a scoped assurance only when every in-scope path is verified, its conditions remain true in the offered configuration and the buyer accepts the defined boundary.
- Do not proceed
- Do not claim no external processing because training is disabled or the model is described as private. If external processing conflicts with a mandatory condition, record the gap; a polished privacy paragraph does not cure it.
- Escalate
- Clarify whether the restriction concerns inference, model training, storage, support access, subprocessors or processing location. Resolve unknown paths before signing; do not substitute an assumed buyer intent.
Keep the decision in the final files
Keep the approved data-flow version, feature conditions and disclosed exceptions connected to the final answer. Recheck affected responses after a connector, provider or deployment changes. REQVERA's final-control role does not itself establish the architecture or certify a no-external-processing guarantee.
See the authentic final-control workflowScope & primary references
Illustrative questionnaire wording, not a customer incident. General supplier-response practice, not a determination of lawful processing. Provider examples apply only to their documented service and configuration; no REQVERA data-processing capability is inferred from them.
- Microsoft: Data, privacy and security for Foundry Models sold by Azure
Primary service-specific documentation separating inference, model training, stateful storage, abuse monitoring and deployment-dependent processing geography. Recheck applicable terms and configuration before reuse.
- Microsoft: Abuse monitoring
Primary documentation showing that modified abuse monitoring requires eligibility and approval. A requested exception is not evidence that it applies.