Your AI Vendor Says Your Data Is Safe. Ask These Questions Before Believing Them

by | Jul 27, 2026 | AI for nonprofits, human-service nonprofit operations, nonprofit, nonprofit Copilot, Nonprofit Technology, organizational knowledge

AI vendors make security sound simple. They promise encryption, privacy, enterprise controls and responsible data handling.

Those claims are not enough.

Before a nonprofit uploads donor records, employee documents, client information or internal policies, leadership needs to understand exactly what the vendor collects, where it goes and who can access it.

A familiar brand, polished demonstration or SOC 2 report does not automatically make an AI product appropriate for sensitive nonprofit work.

What Happens to Your Data?

Start with the most basic question: what does the vendor do with the information users submit?

Ask whether prompts, uploaded files, generated responses and usage records are:

  • Stored after the session ends
  • Used to train or improve models
  • Reviewed by vendor employees
  • Shared with subprocessors
  • Transferred to other countries
  • Included in diagnostic logs
  • Deleted when the account closes

The contract should define these practices. Do not rely solely on a sales representative’s explanation or a general privacy page.

The NIST AI Risk Management Framework Playbook recommends documenting how data is acquired, stored, transformed, maintained and shared, along with applicable retention requirements.

Can the Vendor Prove Its Security Claims?

Ask for evidence appropriate to the risk.

Possible documentation includes independent security assessments, penetration-test summaries, compliance reports, data-processing agreements and incident-response procedures.

The presence of documentation does not eliminate risk. It gives your organization something concrete to evaluate.

The CISA vendor risk-management resources provide structured tools for evaluating vendors instead of accepting security claims at face value.

For higher-risk systems, ask:

  • When was the last independent assessment?
  • What systems and services were included?
  • Were significant problems found?
  • Have those problems been corrected?
  • Will the vendor notify customers about future material findings?

Who Can Access the System?

The vendor should support controls that match the nonprofit’s risk level.

Look for:

  • Multifactor authentication
  • Single sign-on
  • Role-based access
  • Administrator separation
  • Account-removal procedures
  • Audit logs
  • Permission reporting
  • Session controls

A shared account used by an entire department provides little accountability. Each user should have an identifiable account, and access should end promptly when someone leaves or changes roles.

The same principle applies to internal AI knowledge systems. The article on building a permission-aware knowledge hub in Microsoft 365 explains how identity, SharePoint permissions and approved sources should work together.

What Happens When Something Goes Wrong?

Every vendor eventually experiences defects, outages or security events. The important question is how the company detects, reports and resolves them.

Ask the vendor to explain:

  • How quickly customers receive breach notifications
  • What information the notification includes
  • Who investigates incidents
  • Whether customers receive remediation support
  • How backups and recovery work
  • What happens to compromised credentials
  • Whether the vendor preserves evidence for investigation

Can You Leave Without Losing Control?

Vendor exit planning is often ignored during procurement.

The contract should explain how the nonprofit can export its information, how long the vendor retains copies and when backups are deleted. It should also identify any proprietary formats that could make migration difficult.

Your nonprofit should not become dependent on one vendor to retain institutional knowledge. Approved policies, procedures and organizational records should remain under the nonprofit’s control.

A secure assistant such as Maisy is built around governed organizational sources rather than treating a chatbot account as the organization’s permanent memory.

Match the Review to the Risk

A tool used to brainstorm event themes does not require the same scrutiny as a system accessing client records or recommending program decisions.

Classify each proposed use according to the sensitivity of the information, the consequences of failure and the level of access granted.

The board should also understand major AI vendor relationships. Our article on whether nonprofit boards are prepared for AI risk outlines the oversight questions leadership should expect.

The safest vendor is not necessarily the company making the strongest claims. It is the company willing to provide clear answers, contractual protections and verifiable evidence.

Choose tools that protect sensitive information, preserve your ability to leave and help the organization retain institutional knowledge without surrendering control of it.

Pixeldust IT Contract Risk Review Icon

Free Assessment

Complete the form below, and let's talk about how we can help preserve your organizational knowledge and make it easier for your team to find the answers they need.

Name(Required)

Free Guide: The Knowledge Capture Playbook

A practical system for extracting critical knowledge from employees, documents, workflows and real operational cases. This white paper includes prioritization scoring, interview scripts, workshop agendas, capture templates, evidence standards, validation controls, performance metrics and a 30/60/90-day rollout plan.

Download The Free PDF Guide

The Intelligence Compound: A New Operating Model for AI in Small Business

The Intelligence Compound presents a practical framework for implementing AI in small business. Rather than treating AI as a collection of isolated productivity tools, the paper explains how businesses can use it to preserve knowledge, support decisions, reduce owner dependency, identify operational problems, and improve processes over time. It includes original use cases, governance principles, real-world examples, and a 90-day implementation roadmap.

Download Whitepaper PDF