Trust centers for AI companies
Every buyer now asks whether their data trains your model. An AI section on your trust centre answers that and the four questions that follow it.
An AI company's trust centre should state plainly whether customer data is used to train models, which model providers process customer data and where, how long prompts and outputs are retained, whether humans review them, and how customers can turn AI features off. Those are now standard review questions for any product with AI features, not only AI-first companies. Add AI providers to your subprocessor list and, if you hold it, ISO/IEC 42001 certification.
What do buyers ask about AI?
| Question | What to publish |
|---|---|
| Do you train on our data? | A direct yes or no, and the contractual commitment |
| Which model providers see our data? | Named providers, their locations, and their data use terms |
| How long are prompts and outputs kept? | Retention periods, by you and by each provider |
| Do humans review our data? | When, who, and under what controls |
| Can we disable AI features? | Admin controls and defaults |
| How is the AI tested for misuse? | Prompt injection and red team testing cadence, with a letter |
What testing evidence helps?
A letter from an independent AI security assessment or LLM red team exercise answers the misuse question better than a policy. VibeCoded, a sister site in this network, covers AI app security testing and LLM red teaming.
Common questions
Is ISO 42001 worth getting?
It is the AI management system standard and is increasingly asked for by larger buyers. It builds on an ISO 27001 management system, so it is most efficient for companies that already hold or are pursuing ISO 27001.
Is an AI model provider a subprocessor?
Yes, if it processes customer personal data. List it with its location and the data it receives.
Get your AI disclosures published
A trust centre section that answers the AI questions before they are asked.
Get matched