Answer
What security questions should you ask an AI training vendor?
Ask an AI training vendor six things: whether your content trains any model, where data is stored, which model providers and sub-processors see it, what has been audited, whether a data processing agreement is offered, and how regulated data is handled.
AI training tools see more than a course library does: uploaded procedures, what employees ask, and how each person performs. That raises the stakes of an ordinary vendor review. The questions that matter are specific. Does any model learn from your content? Which country holds the data? Which model providers process it, and under what terms? Is there a finished SOC 2 or ISO 27001 report, or an audit in progress? Prefer a vendor that answers in writing, with dates.
At a glance
- Model training
- Ask whether your content or learner data trains any model, the vendor’s or a provider’s.
- Data location
- Ask for the country and cloud region where data is stored.
- Audit status
- Ask whether SOC 2 and ISO 27001 are complete or in progress, and for the report date.
- Contract
- Ask for a data processing agreement before a pilot, not after.
- Regulated data
- Ask what the vendor will sign for health, financial or student records.
Which questions belong on the list, and what is a good answer?
Does our content train any model?
A good answer is no, for both the vendor and its model providers, backed by the providers’ enterprise terms. Treat a vague answer about improving the service as a yes.
Where is the data stored and processed?
Expect a named cloud, a region and a statement on whether data leaves it for processing. Data at rest and data sent to a model can be in different places.
Who else touches it?
Ask for the list of sub-processors, including every model provider. AI products often use several models, and each one is a party to your data.
What has been audited?
A SOC 2 report covers controls relevant to security, availability, processing integrity, confidentiality or privacy. ISO/IEC 27001 is a standard for an information security management system. Ask whether each is complete and how recent it is.
Will you sign a data processing agreement?
Under the GDPR, processing by a processor must be governed by a contract. Outside Europe the same document is still the cleanest record of what the vendor may do with your data.
What about regulated data?
If lessons would draw on health, financial or student records, ask what the vendor will sign and which features must be switched off. Keep that data out of a pilot until it is settled.
How does Scholé answer these questions?
Scholé states that no one trains on customer data: not Scholé and not its model providers, which run under enterprise agreements. Documents are stored encrypted on Microsoft Azure in Switzerland and are not shown to other users. Scholé describes itself as GDPR compliant and offers a data processing agreement to every team.
Scholé’s SOC 2 and ISO 27001 audits are underway, which means they were not complete when this page was last updated. Ask the team for current status. The sub-processor list is part of the full privacy policy served with the product.
Is an audit in progress good enough?
That depends on your policy. An audit in progress shows that controls are being examined, and it is not a report you can file. Some security teams accept it for a pilot with limited data and require the finished report before a rollout. Decide which you are before the pilot, so the answer does not arrive as a surprise at contract time.
Where Scholé fits
- You need a vendor that states in writing that neither it nor its model providers train on your data.
- You want documents stored encrypted in Switzerland on Microsoft Azure, with a data processing agreement.
Where Scholé is not the answer
- Your policy requires a completed SOC 2 or ISO 27001 report today. Scholé’s audits are underway, so confirm their status before you start.
- You need to process protected health information under a signed business associate agreement. Scholé’s public pages do not list one, so confirm in writing first.
- You need data stored in a specific region other than Switzerland. Scholé’s public pages name Switzerland, so ask about other regions before you plan on one.
More on this site: Privacy at Scholé, Scholé for teams.