“We Are Secure” Is Not an Answer, It’s a Slogan
Every vendor selling you an AI solution will say they are secure. This question does not have a yes-or-no answer, and a serious vendor knows how to explain how, not just declare that they are. A manager who doesn’t ask the right questions discovers the gap only after an incident.
The problem grows when AI enters the picture, because it doesn’t just store information. It reads it, analyzes it, and sometimes acts on it. Five areas determine whether an implementation is genuinely secure: where data is stored, how the AI accesses it, who is authorized to do what, how tenants are isolated, and what is logged.
Where Your Data Is Stored, and in What Form
The first question is the most basic, and usually the least asked: where exactly does the data reside, and who besides the vendor can access it. API keys, passwords, and tokens for other systems are just as sensitive as the business data itself, which is why they must be encrypted at rest, not stored as plaintext in a configuration file.
A vendor who answers “in the cloud” and cannot tell you in which region, what encryption is used, and who holds the key, probably hasn’t thought about it seriously. A vendor who can provide a precise answer, including what happens to the data if you stop working with them, already demonstrates a level of maturity.
Encryption in transit (when data is transmitted between systems) is just as important as encryption at rest. If the connection between the agent and your systems runs over an unencrypted protocol, all it takes is for someone to eavesdrop in the middle to read everything passing through.
And don’t forget backups. A backup is a complete copy of your data, and if it is kept without encryption and without access restrictions, all the investment in securing the live system stops right there.
Secure RAG: When AI Reads Your Data
Systems that use RAG (searching a knowledge base before providing an answer) retrieve relevant snippets of information and feed them into the model. The risk is that the index from which the data is fetched isn’t filtered properly, allowing an AI meant to respond to Customer A to pick up an excerpt from Customer B’s database.
Ask the vendor how the index is partitioned: does each customer get a completely separate search space, or does everything reside in a single repository with query-time filtering? The first approach is secure by design. The second relies on the code always remembering to filter correctly—and that is exactly the kind of assumption that breaks systems.
A second question on the same topic: what is retained from the conversations themselves? If everything your employees type is saved on the vendor’s end indefinitely, you end up with a sensitive database you never intended to create.
Permissions: Who Is Authorized to Do What
An AI agent authorized to do everything is convenient today and a risk tomorrow. Solid permissions are defined by role and action type: an agent that reads data doesn’t need write access, and an agent drafting a customer support response doesn’t need access to the advertising budget.
Ask where the line is drawn between what the agent executes autonomously and what requires human approval. An action with financial implications or an irreversible action, such as a major budget change or data deletion, should pause and wait for approval—not run automatically because “that’s what the agent thought was right.”
The principle of least privilege—giving each agent only what it needs for its task and not a sliver more—sounds obvious. In practice, many systems skip it because it’s easier to grant broad access upfront and restrict it later. That restriction almost never happens.
Tenant Isolation: The Most Valuable Check to Request
If the vendor works with multiple clients on the same infrastructure, tenant isolation is a prerequisite, not a nice-to-have feature. The proper rule is deny-by-default: all access is blocked by default, and opened explicitly only to those who are supposed to see it. A system that is open by default and locked down on demand relies on no one ever forgetting to close the door.
Ask for a concrete example: what actually happens if someone tries to access another account’s data through one customer account? A precise answer detailing a clear mechanism is worth far more than any marketing claim.
Proper isolation is also tested at the model level itself. If multiple clients share the same AI session or conversation context, it is easy to inadvertently mix up data. A properly built agent opens a separate context for each client, with no overlap between sessions.
Logs: Who Did What, and When
When something goes wrong, the first question is “who did this?” A system without a clear audit log won’t give you an answer. A good log documents every significant action—including actions performed by an AI agent, not just humans—and records identities in a way that allows investigation without exposing sensitive information to unauthorized eyes.
Ask how long logs are retained, who can view them, and whether you can reconstruct exactly what happened in any anomalous event. A vendor who answers “we’ll check” in real time instead of showing you the log dashboard right then and there probably didn’t build it in advance.
The Checklist to Bring to Your Next Vendor Meeting
- Where our data is stored, and how it is encrypted at rest and in transit.
- How our data is isolated from other clients’ data, at the code level, not just the contract level.
- What permissions each AI agent has, and who approves actions with financial implications.
- What is recorded in the audit log, and for how long.
- What happens to our data if we stop working together.
Agentic AI Services from Fialkov Digital
When we build AI agents for clients, security and privacy are part of the design from day one, not an afterthought. Per-client isolation, secrets encryption, and role-based permissions are built into the infrastructure before the first agent ever goes live.
If another vendor is already offering you a solution, take the five questions above to your next meeting. Precise answers, not general promises, are the only sign you can truly trust. And a vendor who dodges a specific question with a vague answer is an answer in itself.