Processing a prompt is not the same as storing it
A security control can inspect content transiently, retain selected event fields or keep full content, depending on its architecture and configuration. Do not assume every AI security vendor creates a prompt archive, or that no content is retained because processing runs on a device.
Get a written answer for each data category and each party. The location of the security backend, the prompt-inspection path and the AI provider's own handling are separate questions.
Sources checked 20 September 2026. General procurement guidance, not a legal opinion.
Keep three entries in your review record
Use this blank worksheet for the proposed configuration. Keep observed results blank until a real test supplies them.
- Security backend
- Where configuration, account records and retained events are hosted.
- Prompt inspection
- Where prompts or files are processed, and which content is retained.
- Destination AI provider
- The AI account's own processing, storage, training and retention terms.
What evidence should accompany each answer?
Record the data categories, processing and storage locations, retention and deletion terms, subprocessors and support access. Link the applicable contract, architecture or configuration evidence, and name an owner for unanswered questions. A local storage region does not establish the location of every processing or access path.
Blank review worksheet. It contains no observed product results.
A blocked prompt still needs a data-handling answer
A synthetic prompt contains a customer identifier. The policy blocks submission to the AI provider.
The security control has still evaluated the input. Check where that inspection ran, whether any content or event was retained, and who can access the record. A blocked destination request does not prove zero security-service processing or zero telemetry.
Test the exact app, installed client, policy and input path. This example is an evaluation question, not an observed Aona deployment result.
10 questions to ask your AI security vendor
Record answers, evidence and an owner for anything unresolved. Use the same questions for each proposed vendor configuration.
1. Is full prompt or file content retained at all?
Separate transient inspection from retained content, policy events and account metadata. Ask for the actual field list and configuration.
2. Where is each retained data category stored?
Name the location of prompts, files, events, configuration and backups. A cloud-provider name is not a location.
3. Where does processing happen?
Record inspection, classification and any other processing locations separately from storage. Check the exact client and feature combination.
4. Which AI account and provider receive the submission?
Review that provider's terms and account settings separately. The security vendor's region does not establish the AI provider's handling.
5. Which subprocessors can receive or access the data?
Identify their purpose, legal entity and location, and which data categories each can access.
6. Who can access the data for support or administration?
Ask about access locations, permissions and records. Remote access can matter to a transfer assessment even when storage stays local.
7. Is content used for model training or improvement?
Record the purpose and applicable account terms. A no-training statement does not by itself mean no storage or no abuse-monitoring retention.
8. How do retention and deletion work?
Separate content from events and metadata. Include configured periods, backups, exit deletion and any documented exceptions.
9. Which agreement and transfer mechanism apply?
Keep the DPA, applicable order or regional commitment, subprocessors and any transfer assessment together. Identify unresolved questions before approval.
10. What evidence supports the answer?
Review the relevant architecture, configuration, synthetic test and independent assurance report. An assurance badge is not a data-flow map.
A region is one part of a transfer assessment
EU and UK transfer rules concern the relevant disclosure or access to personal data, not only the physical storage address. An overseas recipient, support access, subprocessors or onward processing may need separate assessment.
Under the EU framework, applicable adequacy decisions and Article 46 safeguards are different transfer routes. The ICO likewise distinguishes UK adequacy, appropriate safeguards and exceptions. Check the actual entities, purposes and applicable route with your privacy or legal team.
How to use public documentation
A trust page, architecture document and DPA serve different purposes. Use public documentation to identify the right questions, then verify the agreement and configuration that apply to your deployment. Missing public detail is an open question, not proof that a vendor lacks the control.
Retain the document version, source date and relevant scope. Revisit the review when a client, provider account, subprocessor or data-handling setting changes.
Aona's hosting and processing choices
Aona's backend can run in your cloud, on-premises or on Aona-managed servers. Prompt processing can run on the user device, in your environment or on Aona-managed servers. Confirm the supported combination and the fields retained for the required controls.
The seven Aona-managed regional options are Australia, France, the United Kingdom, Germany, the United States, Singapore and Hong Kong. The AI provider's processing, storage and account terms remain separate.
Aona has completed a SOC 2 Type II examination covering Security, Confidentiality and Availability. Request the report to review the auditor’s findings and the full system scope. Data retention is configurable per customer, for example 30, 90 or 180 days. Agree retention and deletion settings for the data in your selected deployment.