Scholé AI

Answer

What security questions should you ask an AI training vendor?

Ask an AI training vendor six things: whether your content trains any model, where data is stored, which model providers and sub-processors see it, what has been audited, whether a data processing agreement is offered, and how regulated data is handled.

AI training tools see more than a course library does: uploaded procedures, what employees ask, and how each person performs. That raises the stakes of an ordinary vendor review. The questions that matter are specific. Does any model learn from your content? Which country holds the data? Which model providers process it, and under what terms? Is there a finished SOC 2 or ISO 27001 report, or an audit in progress? Prefer a vendor that answers in writing, with dates.

At a glance

Model training
Ask whether your content or learner data trains any model, the vendor’s or a provider’s.
Data location
Ask for the country and cloud region where data is stored.
Audit status
Ask whether SOC 2 and ISO 27001 are complete or in progress, and for the report date.
Contract
Ask for a data processing agreement before a pilot, not after.
Regulated data
Ask what the vendor will sign for health, financial or student records.

Which questions belong on the list, and what is a good answer?

  1. Does our content train any model?

    A good answer is no, for both the vendor and its model providers, backed by the providers’ enterprise terms. Treat a vague answer about improving the service as a yes.

  2. Where is the data stored and processed?

    Expect a named cloud, a region and a statement on whether data leaves it for processing. Data at rest and data sent to a model can be in different places.

  3. Who else touches it?

    Ask for the list of sub-processors, including every model provider. AI products often use several models, and each one is a party to your data.

  4. What has been audited?

    A SOC 2 report covers controls relevant to security, availability, processing integrity, confidentiality or privacy. ISO/IEC 27001 is a standard for an information security management system. Ask whether each is complete and how recent it is.

  5. Will you sign a data processing agreement?

    Under the GDPR, processing by a processor must be governed by a contract. Outside Europe the same document is still the cleanest record of what the vendor may do with your data.

  6. What about regulated data?

    If lessons would draw on health, financial or student records, ask what the vendor will sign and which features must be switched off. Keep that data out of a pilot until it is settled.

How does Scholé answer these questions?

Scholé states that no one trains on customer data: not Scholé and not its model providers, which run under enterprise agreements. Documents are stored encrypted on Microsoft Azure in Switzerland and are not shown to other users. Scholé describes itself as GDPR compliant and offers a data processing agreement to every team.

Scholé’s SOC 2 and ISO 27001 audits are underway, which means they were not complete when this page was last updated. Ask the team for current status. The sub-processor list is part of the full privacy policy served with the product.

Is an audit in progress good enough?

That depends on your policy. An audit in progress shows that controls are being examined, and it is not a report you can file. Some security teams accept it for a pilot with limited data and require the finished report before a rollout. Decide which you are before the pilot, so the answer does not arrive as a surprise at contract time.

Where Scholé fits

  • You need a vendor that states in writing that neither it nor its model providers train on your data.
  • You want documents stored encrypted in Switzerland on Microsoft Azure, with a data processing agreement.

Where Scholé is not the answer

  • Your policy requires a completed SOC 2 or ISO 27001 report today. Scholé’s audits are underway, so confirm their status before you start.
  • You need to process protected health information under a signed business associate agreement. Scholé’s public pages do not list one, so confirm in writing first.
  • You need data stored in a specific region other than Switzerland. Scholé’s public pages name Switzerland, so ask about other regions before you plan on one.

More on this site: Privacy at Scholé, Scholé for teams.

Related questions

Some do and some do not, so ask each vendor directly and get the answer into the contract. Scholé states that neither it nor its model providers train on customer data.

SOC 2 is an auditor’s report on a service organization’s controls relevant to security, availability, processing integrity, confidentiality or privacy. ISO/IEC 27001 is a certifiable standard for an information security management system. Many buyers ask for both.

At the start. Ask for the data processing agreement, the data location and the audit status in the first week, so the review does not begin after the pilot has ended.

Scholé states that documents are stored encrypted on Microsoft Azure in Switzerland.

Still have questions?

Can’t find what you’re looking for?

Send us a question

Sources

  1. What organizations ask before buying AI training: findings from 82 conversations with 45 organizations, February to September 2026. Scholé, read 2026-10-01.
  2. System and Organization Controls: SOC suite of services. AICPA and CIMA, read 2026-10-01.
  3. ISO/IEC 27001: information security management systems. International Organization for Standardization, read 2026-10-01.
  4. Art. 28 GDPR: Processor. General Data Protection Regulation, as published by intersoft consulting, read 2026-10-01.
  5. Scholé plans and pricing. Scholé, read 2026-10-01.
  6. Privacy at Scholé. Scholé, read 2026-10-01.

Last updated 2026-10-01. Statements about Scholé repeat its public pages, and its plans and audits change over time. Think something here is wrong or out of date? Email team@schole.ai and we will correct it.

Rather find out than read about it?

Start free, no sales contact and no credit card.