Evidence already available
Commercial
- Which products and connectors are included?
- How are seats, tokens, overages, Model Router balance, and provider charges measured?
- What are invoice, renewal, refund, and credit-expiry terms?
- Which usage limits apply?
- What happens when a limit is reached?
Security and privacy
- Which certifications and reports are current?
- Which subprocessors and model providers are used?
- Are customer inputs or outputs used for training?
- What are product-specific retention and deletion periods?
- Which processing regions and transfers apply?
- How are secrets encrypted, accessed, and rotated?
- How is tenant isolation tested?
- What support and debugging access exists?
- Which penetration-testing rules apply?
Identity and audit
- Are SSO/SAML, SCIM, MFA, and domain enforcement included?
- Which roles and task permissions exist?
- Which actions are audited?
- Can audit events be exported to a SIEM?
- How long are audit events retained?
- How are sessions revoked?
Reliability and support
- Availability commitment
- Support hours and severity definitions
- Backup and recovery objectives
- Incident-notification timeline
- Status page and escalation path
- Change and maintenance windows
- Hosted and customer responsibility split
Exit
- Export formats and assistance
- Data-deletion process and evidence
- Connector and credential revocation
- Historical analytics behavior
- Backup expiry
- Account closure and final invoice