· 7 min read
How to Evaluate a Private AI Vendor
A practical checklist for evaluating a private AI vendor: environment, data handling, model terms, access control, logging, and ongoing support.
Evaluating a private AI vendor comes down to six questions: where does the deployment run, what happens to your data, which model providers are involved and under what terms, how is access controlled, what gets logged, and who is responsible for operating it after launch. A vendor that cannot answer these in specific, verifiable terms is not ready for your company's data. This checklist walks through each question and what a real answer looks like.
1. Where does the deployment actually run
Ask whether your company gets a dedicated environment or a seat in a shared, multi tenant system. A dedicated environment means your documents, conversations, and configuration live in infrastructure provisioned for your company alone. A shared system relies on logical separation inside one pool of tenants. Both can be secured, but you should know which one you are buying and get the boundary described in writing, not just asserted on a sales call.
2. What happens to your data
Ask where documents and conversations are stored, how long they are kept, who can access them internally at the vendor, and what the deletion process looks like when you offboard a user or end the contract. A vendor should be able to name the storage location and retention setting for your specific configuration rather than pointing to a general privacy policy.
3. Which model providers are involved, and under what terms
Most private AI products are not a single proprietary model. They are an application layer that sends configured requests to one or more model providers. Ask which providers are supported, what data crosses to each provider's endpoint, and what that provider's retention and training terms are for the specific agreement in place. Do not accept a blanket claim that data is never used for training without the underlying provider terms to verify it against.
4. How access is controlled
A private AI deployment should mirror how your company already restricts access to documents and systems, not grant every user the same unlimited assistant. Ask how permissions are assigned, whether access follows your existing identity provider, and what happens to a user's access when their role changes or they leave the company.
5. What gets logged, and who reviews it
Ask what activity is logged, who can see those logs, how long they are retained, and whether logging can support an internal review or a client security questionnaire. A deployment without usage visibility gives you no way to investigate a mistake or answer a reviewer's question about how the system was actually used.
6. Who operates it after launch
Ask who is responsible for updates, model changes, uptime, connecting new data sources, and support once the initial deployment is done. Some vendors hand you a system and step back. Others stay on as the operator. Get the ongoing responsibilities written into the agreement, not left as an assumption from the sales conversation.
Checklist to bring to a vendor call
- Is our environment dedicated to us, or shared with other tenants
- Where is our data stored, and what is the retention setting
- Which model providers are used, and what are their current data handling terms
- How is access assigned, and does it follow our existing identity provider
- What is logged, who can see it, and for how long
- Who operates the deployment after launch, and what does that include
- What is excluded from the proposed scope, and what would change the price
A vendor that can document its architecture
The clearest signal in a vendor evaluation is not a feature list. It is whether the vendor can describe its own architecture in specific terms: the environment boundary, the stored data, the connected model providers and their terms, the access model, the available logging, and the operating responsibilities once you are live. HummingAgent AI documents each of those for a Private GPT deployment, reviews the security model with your team, and scopes pricing after your requirements are understood. Book a meeting to walk through the architecture for your company.