Security

What 'Your Data Stays Yours' Should Actually Mean

22 August 20266 min read
ShareX / TwitterLinkedIn

'Your data stays yours' has become the most-repeated phrase in AI sales — and one of the least examined. It can mean almost anything, which is convenient for vendors and useless for you. If you're putting customer data through any AI system, here are the specific questions that turn a slogan into something you can verify.

Question 1: Is My Data Used to Train Models?

The first and most important question, with a precise answer available. Reputable AI providers offer commercial terms under which your inputs are never used for model training — this is standard for business API access from the major model providers, as distinct from free consumer tools where your prompts may become training data. Any vendor building on AI should be able to state, in writing, that client data is not used to train models — theirs or anyone else's. If the answer is vague, that's your answer.

Question 2: Who Else Is on My Server?

Most software is multi-tenant: your data and a thousand other customers' data in one database, separated by access rules. Usually fine — until a misconfiguration makes it not fine, at which point the blast radius is everyone. The stronger model is per-client isolation: your workflows and data on dedicated infrastructure that no other customer shares. Isolation is also the one security property a non-technical buyer can fully understand: my server, my data, nobody else on the box.

Question 3: Which Country Does It Sleep In?

Data residency matters for UK businesses — for GDPR clarity, for client contracts that specify it, and for regulated sectors where it's non-negotiable. Ask where the servers are, and don't forget the second half everyone misses: where do the backups live? A UK server backed up to another continent is a residency story with an asterisk. UK workloads and UK backups is the clean answer.

The full checklist for any AI vendor:

  • No model training on client data — stated in writing, not implied
  • Per-client infrastructure isolation, not just logical separation
  • UK or EU residency for both workloads and backups
  • Read-only access to your systems by default; write access granted per approved workflow
  • Encrypted backups that are actually restore-tested — ask when they last proved it
  • A data processing agreement they offer before you ask
  • An exit path: your data and workflows exported and returned when you leave

The single best due-diligence question: 'When did you last restore a backup, and how do you know it worked?' Vendors with real answers give dates. Vendors without give assurances.

The Right to Leave Is a Data Right

The least-discussed part of data ownership is what happens when the relationship ends. If your workflows, history, and configuration can't leave with you, then in the way that matters most, the data was never really yours. Ask what off-boarding looks like before you onboard: what gets exported, in what format, and what gets deleted from the vendor's side afterwards. Good vendors have a ready answer, because they built for it. It's also the ultimate accountability mechanism — a vendor you can leave easily is a vendor with a permanent incentive to be worth staying with.

None of this requires a security team to evaluate. Seven questions, all with checkable answers. The vendors who mean 'your data stays yours' will enjoy answering them — it's the ones who don't that the checklist exists for.

Ready to deploy your AI agent?

Our engineers connect your systems and build workflows like these for you — live in five working days, supported from then on.

Book a discovery call