In Part 1, I argued that your competitive edge leaks not through theft but through the plumbing: logs, caches, sub-processors, and the quiet gaps nobody drew a line around. I ended on a question. Where is your line?
Here is the unglamorous answer. Your line lives in a contract. Not in a vision statement, not on a vendor's trust-center page with its reassuring padlock icon, but in the master services agreement and the data processing addendum that no one on the executive floor has actually read. Sovereignty is won or surrendered in that document. Usually surrendered, usually by default, usually because the people who understood the stakes were not in the room when it was signed.
So before you sign the next one, ask these seven questions. Not the ones procurement asks. The ones that decide whether your alpha stays yours.
1. Does our data train your models, and does "your models" include everyone downstream?
The first answer is easy and usually reassuring: no, enterprise data is excluded from training. Good. Now ask the second half, because that is where it turns slippery. Does the exclusion follow your data to every sub-processor, every embedded model, every third party in the chain? A promise that binds the vendor and evaporates one hop downstream is not a promise. It is a press release. The tell: if they can only vouch for their own systems, you have just found the edge of your protection, and it sits closer than you thought.
2. Where does our data physically live, and whose laws reach it?
Data carries a passport. It sits on servers in a specific country, subject to that country's laws and the reach of its authorities, no matter where you signed. Ask for the actual regions, not "the cloud." Then ask what happens on failover, because your data can take an unannounced holiday to a jurisdiction you never approved the moment a data center hiccups. The tell: vagueness about regions, or a clause letting them relocate data "for operational reasons" with no notice to you.
3. What do you log, for how long, and who gets to read it?
Every prompt is a record. Some vendors log inputs and outputs for safety or quality, keep them for months, and route a sample to human reviewers you have never met. None of that is sinister. All of it is a copy of your alpha resting somewhere you do not control. Ask for retention measured in days, deletion on request, and a straight answer on whether humans ever see your content. The tell: "we may retain data as needed." Needed by whom, and for how long, is the entire question.
4. Is there a caching layer, and can our data surface in someone else's session?
Caching makes things fast and occasionally makes things awkward, the awkwardness being one tenant's data warming a cache another tenant can feel. Ask whether caches are isolated per customer, and how bleed between tenants is prevented. The tell: a blank look. If the person across the table has never considered the question, it is safe to assume the architecture has not either.
5. Who are your sub-processors, and are they bound by the terms we just negotiated?
Page one is the vendor you are talking to. Page forty is the list of companies that vendor quietly relies on, and your hard-won protections are only as strong as the weakest name on it. Ask for the current sub-processor list, the right to be notified before it changes, and written confirmation that your terms flow down to all of them. The tell: no list, or a list wrapped in the right to add anyone, anytime, without telling you.
6. When you are breached, when and how do we find out?
Someone is eventually breached. "Without undue delay" is not a timeline, it is a lawyer's shrug. Ask for a number in hours. Ask what event starts the clock, and whether you receive real forensic detail or a sanitized paragraph. The tell: a notification window that only begins once they "confirm" an incident, which can quietly mean weeks after they first suspected one.
7. When we leave, what happens to our data, our fine-tunes, and our embeddings?
This is the one everyone forgets during the honeymoon of onboarding. Your raw data is easy to picture walking out the door. Harder to picture: the model you fine-tuned on that data, and the embeddings that encode your business in vector form. Those are your alpha wearing a new outfit. Ask whether they are deleted, exportable, or quietly retained after the relationship ends. The tell: a deletion promise that covers the files you uploaded but goes conspicuously silent on everything derived from them.
The question behind the questions
Notice that not one of these asks how good the model is. That is deliberate. Capability is no longer the scarce thing. The models are all clever enough and getting cleverer at roughly the same pace. Every question above is about control, because control is the only advantage still in short supply.
There is a simpler way to use this list. You do not need to become fluent in caching architecture or sub-processor law. You need to watch how the vendor answers. The right partner handles all seven crisply, in numbers, in writing, perhaps with a flicker of pride that you bothered to ask. The wrong one reaches for adjectives. Robust. Enterprise-grade. Bank-level. Adjectives are what people offer when they do not have numbers.
The contract is where your line stops being a metaphor and becomes something a court could enforce. Ask the seven questions, and let the evasions tell you everything the sales deck will not.