← All sheets
GL-S-005Sheet 005FOR INFORMATIONS · SECURITY

"Who sees our customer data?" Four answers. One survives an auditor.

SCHEDULE · THE SUB-PROCESSOR QUESTION · SECURITY QUESTIONNAIRES

Drawing sheet 005: "Who sees our customer data?" Four answers. One survives an auditor.

General notes

  1. 01Procurement asks this on every serious deal now. Engineering teams give one of four answers.
  2. 02Only A holds under questioning. D holds only if you can show the log.

Schedule of answersWhat each one sounds like to the auditor

RefAnswerWhat the auditor hears
AThe model provider is listed, with what it receivesSomeone did the work
BThe provider is listed, but not what it receivesThe list exists. The evidence does not.
CIt is not on the list yetHonest. Also the most common.
DWe strip personal data before it leavesShow me the log

As posted

"Which sub-processors see our customer data?"

Procurement asks it on every serious deal now, and every engineering team gives one of four answers. I have heard all four from teams shipping AI features on top of real customer data.

A. The model provider is listed, with exactly what it receives. B. The provider is listed, but nobody can say what it receives. C. It is not on the list yet. D. We strip personal data before it leaves, so it does not need to be.

Only A holds under questioning. B means the list exists and the evidence does not, which an auditor notices in about a minute. C is the most common answer and the most honest one. D holds only if you can produce the log proving the stripping happened before the request left.

This is not a legal formality. It is a boundary question. Your prompt leaves your infrastructure and lands in someone else's, and the list is how you admit that in writing.

If the answer cannot be written down today, that is the work. It is smaller than it looks, and it gets much bigger the week a customer's security team asks first.

Sheet 005.

Read with

  • Sheet 004 · Your prompt is a data export. Who's on the receiving end?
  • Sheet 015 · The auditor asks for the log. Provider logs prove receipt, not removal.