Quick answer
Seven questions separate an AI vendor’s marketing from its architecture, and every one can be checked without the vendor’s cooperation. Ask about model ownership, what “learns” means, model retirement, data location and sub-processors, whose certifications those are, the context behind each number, and what is not published. Then verify each answer against the vendor’s own documentation. Silence is a finding, not a gap.
Why “their website says nothing about this” is a result, not a dead end
Most AI vendor evaluations fail in the same place: a good question gets a confident answer in a meeting, the answer goes into a scorecard, and nobody checks it against anything the vendor has committed to in writing.
The fix is not scepticism. It is knowing which published artefact settles each question. Mature vendors publish sub-processor lists, deprecation schedules and compliance documentation as a matter of routine, because enterprise procurement demands them. So the absence of such a page is informative and citable: writing “not published” in your notes accuses nobody of anything. This pairs with our voice-AI vendor security questionnaire on recordings, PII and retention.
The seven questions at a glance
| The question | What a solid answer contains | How to verify independently |
|---|---|---|
| Is the model yours, or are you orchestrating someone else’s? | A named base model and provider, or a model card | Sub-processor list, trust centre, job ads |
| What does “learns” mean, and is the loop scoped to my account? | The mechanism, plus the tenancy boundary | DPA clauses on aggregated or de-identified data |
| What happens when the base model is retired? | A migration and re-evaluation process | The model provider’s published deprecation page |
| Where does my data live, and who is the sub-processor? | Named entities, regions, purposes | The vendor’s published sub-processor list |
| Which certifications do you hold, and which belong to your providers? | Certificate holder, service in scope, audit period | Trust centre and per-service compliance pages |
| Can you show me that number in context? | Sample size, date, method, who ran it | Follow the citation to the primary source |
| What is not published? | A direct list, offered without defensiveness | Search their domain for each artefact first |
1. Is the model yours, or are you orchestrating someone else’s?
Ask: “Which foundation model does this product call at inference time, and who operates it?”
A good answer names a base model and a provider, or offers a model card if the vendor genuinely trained weights. Orchestrating a frontier model is a respectable architecture. Being unable to say which one is not.
A hand-wave sounds like “our proprietary AI engine” or “a blend of models tuned for sales”. Both are true of nearly every product in the category, so they tell you nothing. We take the whole ladder apart in what “proprietary AI” actually means in sales tech.
Verify it yourself. The sub-processor list is the fastest route, because model providers act as processors and are normally disclosed there. Twilio, for example, publishes a page headed “Twilio Sub-Processors” with columns including “Nature and purpose of processing” and “Location(s) of processing”; the version marked “Last Updated: April 2026” lists both Anthropic and OpenAI against “All AI Products” (Twilio, Sub-Processors, checked 30 August 2026).
2. What exactly does “learns” mean here, and is the loop scoped to my account?
Ask: “When you say the agent learns, what changes — the prompt, the retrieval index, the routing rules, or model weights? And does anything derived from my conversations reach another customer’s agent?”
A good answer names the mechanism and the tenancy boundary together: what is per-account, what is aggregated, and whether aggregation is contractual and opt-out-able.
A hand-wave is “it gets smarter with every conversation”, with no named mechanism. Better prompts and retrieval are real engineering, but that is authored improvement, not emergent intelligence — the distinction we walk through in do AI sales agents actually learn?
Verify it yourself. The data-processing addendum is where this becomes binding, not the marketing page. Look for clauses permitting use of “aggregated” or “de-identified” data for service improvement. If the DPA and the documentation are both silent, the tenancy boundary is undefined.
3. What happens when the base model you depend on is retired?
Ask: “The model underneath this will be retired eventually. What is your migration and re-evaluation process, and how much notice do you get?”
A good answer describes a regression suite run against the replacement before switching, and admits that prompts tuned against one version do not automatically hold on the next.
A hand-wave is “we always run the latest model” — an outcome, not a process, and one that quietly implies behaviour never changes underneath you.
Verify it yourself. Model providers publish this. Anthropic’s deprecations page defines four lifecycle states — Active, Legacy, Deprecated and Retired — and states that “Anthropic notifies customers with active deployments for models with upcoming retirements, providing at least 60 days’ notice before model retirement for publicly released models” (Anthropic, Model deprecations, checked 30 August 2026). Once question 1 names the provider, you know the notice window your vendor works inside.
4. Where does my data live, and who is the sub-processor?
Ask: “Which entities process our data, in which countries, for what purpose, and how will we be told when that list changes?”
A good answer is a link, not a paragraph: named entities, regions and purposes, plus a way to subscribe to changes.
A hand-wave is “your data is stored securely in the cloud”. Residency and sub-processing are different questions: data can sit in-region while a processor outside the region has access to it. You need both answers, and only one is usually on the marketing site.
Verify it yourself. Search the vendor’s domain for “sub-processor” or “subprocessor”. The Twilio list above shows the shape a usable one takes: purpose and location, per entity, per service, with a revision date.
5. Which certifications do you hold, and which belong to your infrastructure providers?
Ask: “Whose name is on the certificate, which services are in scope, and what period does the report cover?”
A good answer separates the two cleanly. HubSpot’s security page does it in one sentence — “HubSpot products are hosted with cloud infrastructure providers with SOC 2 Type 2 and ISO 27001 certifications, among others” — stated apart from HubSpot’s own SOC 3 and confidential SOC 2 Type 2 reports (HubSpot, Security, Privacy, and Control, checked 30 August 2026).
A hand-wave is “we are SOC 2 compliant” with no report, no scope and no period. Certification also has boundaries: AWS’s compliance programs page states that “AWS customers remain responsible for complying with applicable compliance laws, regulations and privacy programs” (AWS, Compliance Programs, checked 30 August 2026). Your vendor inherits the infrastructure controls. It does not inherit the certificate.
Verify it yourself. Scope is per-service, not per-company, and good trust centres are built that way: Salesforce’s compliance site gives Agentforce & Einstein Platform, Data Cloud and Heroku their own entries, because “Each service includes detailed documentation and compliance information to help you meet regulatory requirements” (Salesforce Compliance, Services, checked 30 August 2026). Check the product you are buying is the one named.
6. Can you show me that number in context — sample size, date, and who ran the study?
Ask: “Where does that figure come from — how many accounts, over what period, measured how, and who ran it?”
A good answer supplies a denominator and a date, and separates the vendor’s own operating data from independent research. First-party figures are legitimate evidence, just a different class of it.
A hand-wave is a percentage with no base. Watch for borrowed statistics: a number is quoted by an analyst, repeated in a blog post, then cited to the blog post rather than the study.
Verify it yourself. If a figure cannot be restated as “X out of Y, over period Z, measured by W”, it is not a number you can put in a business case.
7. What is not published?
Ask, verbatim: “What have you deliberately not published yet, and why?”
This is the highest-yield question on the list, and almost nobody asks it. A vendor who answers directly — no certification yet, no public pricing, no architecture whitepaper, and here is why — has told you more about its maturity than any demonstration. A hand-wave is treating the question as hostile.
Verify it yourself by searching the vendor’s domain for each artefact before the call, so you already know the answer and are testing candour, not fishing.
The same seven questions, applied to Zian
A checklist its author cannot survive is worth nothing. So, unhedged:
1. Model ownership. Zian orchestrates and optimises; we do not pretrain a foundation model. SmartReach AI™ and PrecisionPitch AI™ are orchestration and split-testing layers, and private deployment answers where inference runs, not who trained the weights.
2. Learning and tenancy. What improves is scripts, sequencing, channel and timing, driven by continuous split-testing against real outcomes — not model weights. We have not published an architecture document defining that loop’s tenancy boundary. On this checklist’s own terms: unpublished, and one to settle in contract.
3. Model retirement. We have not published a model deprecation or migration policy. Not published.
4. Data location and sub-processors. We do not publish a sub-processor list. Private model deployment on customer infrastructure is available, which changes where processing happens, but is not a substitute for the list.
5. Certifications. Zian holds no published security certification. No SOC 2, no ISO 27001, no HIPAA attestation. Our security and privacy page states that the independent certifications commonly asked about are held by the infrastructure and AI providers we build on — the exact distinction question 5 exists to draw. Any assurance we offer is contractual and architectural, not certified.
6. Numbers in context. The headline figures on zian.ai are ours, and the operating figures behind them — outbound acquisition since 2017, a learning engine tracking around 420,000 data points across more than 10,000 leads a day — are first-party owner data, not an independently audited study. We publish no per-campaign denominators. Weigh them accordingly.
7. What is not published. No security certification, no sub-processor list, no deprecation policy, no public pricing and no self-serve signup: Zian is in an application-gated partnership beta by design, and pricing is set per deployment.
None of that is comfortable to write. It is what we would want a buyer to have before a first call.
Frequently asked questions
Is it fair to score a vendor down for something they simply have not published?
Yes, provided you record it as unverified rather than as a failure. Documentation is a recognised part of trustworthy AI practice: the NIST AI Risk Management Framework, released 26 January 2023, “is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems” (NIST, AI Risk Management Framework). A vendor that has done the thinking usually has the artefact.
Does my vendor’s cloud provider being certified mean my vendor is covered?
No. Infrastructure certification covers infrastructure controls. AWS’s compliance programs page is explicit that “AWS customers remain responsible for complying with applicable compliance laws, regulations and privacy programs” (AWS, Compliance Programs). The application layer, the access model and the data handling are your vendor’s, and need their own evidence.
How many of these seven can I check before I ever contact the vendor?
Realistically, five. Model provider, sub-processors, certifications, deprecation exposure and unpublished artefacts are all determinable from public pages. That leaves only the tenancy boundary and the provenance of specific numbers to ask about.
Should I expect a startup to pass all seven?
No, and used that way the checklist becomes a proxy for company size rather than a measure of risk. The signal is not whether every artefact exists; it is whether the vendor knows which are missing and says so unprompted.
Run the checklist on us
If you would rather have those seven answers in writing before a first meeting, that is the conversation we want. Zian is in an application-gated partnership beta, so every engagement starts with a scoped discussion. Apply For Partnership and bring the checklist.