Your First Business Customer Sent A Security Questionnaire: What Your AI Product Needs To Answer It
A buyer's security review asks different questions from a launch checklist. The eight answers a small AI vendor needs ready before the questionnaire lands.
Contents
The Gate Is A Spreadsheet, Not A Bug Report
1. Tenant Isolation: A Design Answer, Not A Toggle
2. Who On Your Team Can See Customer Data
3. An Audit Trail, Which Is Not Your Application Log
4. Retention And Residency: Two Answers You Must Write Down
5. The Subprocessor List, Including Every AI Model In Your Chain
6. A Data Processing Agreement You Can Actually Sign
7. Incident Response And Breach Notification
8. Do You Actually Need SOC 2, ISO 27001 Or Essential Eight Yet
Frequently Asked Questions
Get your answers and evidence ready before the questionnaire arrives
buildAgency builds AI products with the artefacts a business buyer's security review asks for: a stated isolation model, an audit trail, a subprocessor list and a DPA you can sign. Melbourne-based, fixed price, and we help you answer the questionnaire.
See How buildAgency WorksRelated Guides
Building Software in Australia: What the Privacy Act and ACL Actually Require of Your App
A plain-English look at how the Privacy Act 1988 and Australian Consumer Law apply to software you commission, with a practical compliance checklist.
From Vibe-Coded MVP to Production: The Order to Do the Work In
The ten-step sequence for taking an AI-generated prototype to production, and why doing auth, security and monitoring out of order costs you weeks.
How To See What Your AI Agent Is Doing Without Reading A Log File
Six things get sold as agent visibility and they answer different questions. What Zapier, Make and n8n actually show an owner, and where retention fails.