Two magenta light fields overlapping on black, the shared zone brightest, protecting proprietary data with vendors
Due Diligence • 8 min read

Questions to Ask Vendors About Protecting Proprietary Data

Questions to ask vendors about protecting proprietary data in collaborative scenarios cover ownership, retention, isolation, subcontractors, and model training. IBM's 2026 study found supply chain compromise added about $227,250 above the average breach cost.

The questions to ask vendors about protecting proprietary data in collaborative scenarios are ownership, retention, isolation, subcontractors, and model training. Collaboration is where data leaves the boundary you drew for it. IBM's 2026 breach study found business partner and supply chain compromise added more cost than any other factor measured, about $227,250 above the global average.

I am Amelia S. Gagne, CEO of Kief Studio. This page is specifically about shared work: joint projects, client-vendor workspaces, subcontractors, and co-development. The general purchase questionnaire is what to ask your vendors about security. The regulated-industry framing is building for regulated industries.

Two magenta light fields overlapping on black, the shared zone brightest, protecting proprietary data with vendors
The overlap is the whole problem. Neither party's normal policy describes the shared zone, so the shared zone is where no policy applies.

Why collaborative scenarios leak differently

A normal vendor relationship has a direction. You hand over data, they process it, they hand back a result. A collaborative one does not. Both sides contribute, the artifact is joint, and the boundary moves as the work moves.

Three specific failure modes follow from that.

Nobody owns the shared surface. Your security policy covers your systems. Theirs covers theirs. The shared Slack Connect channel, the joint repository, and the design file with comment history belong to neither policy.

Access outlives the project. Collaboration accounts are created in a hurry and removed slowly, or not at all. The account that still has read access to the shared drive eighteen months later is the most common finding in this category.

Derived artifacts escape the contract. The contract covers "your data." It rarely covers the summary, the model, the benchmark, or the case study built from your data. That is where proprietary value actually leaks.

IBM's finding is consistent with this. Supply chain compromise tied for the longest breach lifecycle in the 2026 study at 258 days, against a 247-day mean. Shared environments are slow to detect because everybody assumes the other side is watching.

What questions should you ask about ownership and derived work?

  • Who owns the output, and who owns the intermediate artifacts? Name the deliverable, the working files, the analysis, and the anonymized aggregate separately. Vendors often concede the first and keep the last.
  • Can you use our data to improve your product? Ask it directly. "Improve our services" in a terms-of-service document is broad enough to cover a great deal.
  • Can you publish about this engagement, and who approves? Written approval per instance, not a blanket grant at signature.
  • What happens to jointly created material if we stop working together? The answer at signing is much better than the answer at termination.
  • Is our material used to train any model, yours or a third party's? Get it in the contract, not in a support ticket. Product defaults change.

That last question is now the main event. The vendor's own AI features are frequently powered by a subprocessor, and the subprocessor's terms are the ones that actually govern. The sub-processor problem covers the general shape. Building an AI policy for your team covers your side of it.

A magenta aggregate forming above dim source records on black, derived artifacts in vendor collaboration
Anonymized aggregates are often carved out of the confidentiality clause entirely. For a small company, the aggregate can be the proprietary part.

What questions should you ask about isolation and access?

These are the operational ones. They are answerable with a screenshot, which is how you know whether the answer is real.

  • Is our collaborative workspace isolated from your other clients, and how? Separate tenant, separate project, separate encryption key, or just separate folder names.
  • Who on your side has access, and can you produce the list today? The delay in producing the list tells you whether anyone manages it.
  • How do you remove access when someone leaves your team mid-project? Ask for the offboarding trigger, not the intent.
  • Are your people using their own accounts, or a shared one? Shared credentials destroy attribution. If the agent or automation has its own login, that is the right answer, and the reasoning is in what is a non-human identity for an AI agent.
  • What logging exists on the shared surface, who can read it, and how long is it kept? If only the vendor can see the logs, you have no independent record.
  • Which of your subcontractors will touch this work? Named, before they start.

The Cloud Security Alliance's CAIQ v4.1 added columns for the Shared Security Responsibility Model specifically so a provider has to mark which side owns each control. If your vendor has a completed CAIQ, those columns are the fastest read in the document.

A magenta roster of lit and unlit entries on black, the access review in vendor collaboration data protection
How long a vendor takes to produce the access list tells you whether access is managed or merely granted.

What should you ask about retention and exit?

Exit questions are asked least and matter most, because the collaboration ends and the copies do not.

  1. What is your retention period for our material after the project closes, and what triggers deletion?
  2. Does deletion include backups, and if not, when do the backups age out?
  3. Will you confirm deletion in writing?
  4. How do we get our material back, in what format, and how long does that take?
  5. What survives in your systems by design: invoices, tickets, email threads, the support transcript with the screenshot in it?

Item five is the honest one. Support tickets and email attachments are the durable copies nobody lists in a data inventory. The cleanest mitigation is not asking better deletion questions, it is sharing less in the first place, which is the argument in data you don't keep can't leak.

A magenta thread ending cleanly against dim residual traces on black, retention and exit in vendor data protection
Deletion that excludes backups is common and often reasonable. The point is to know the actual window rather than assume zero.

Is there a standard you can point at?

For most commercial work, no single standard governs. Three are worth borrowing from.

NIST SP 800-171 is written for contractors handling controlled unclassified information. Revision 3 was published in May 2024 with 97 requirements across 17 families, adding a Supply Chain Risk Management family that Revision 2 did not have. Note that for defense contracts it is not yet the operative baseline: a DoD class deviation keeps Revision 2 in force, and CMMC Level 2 remains anchored to Revision 2's 110 requirements. If you are borrowing the structure rather than certifying, Revision 3's SR family is the useful part.

NIST SP 800-161r1 is the supply chain risk management guidance. It is 326 pages and written for federal agencies, but the control families translate.

CSA CAIQ is the practical one. CAIQ v4 has 261 yes-or-no questions across 17 domains, and CAIQ-Lite trims that to 124 for early screening. For a small company assessing a collaboration partner, CAIQ-Lite plus the ownership questions above is a proportionate process.

Borrowing structure beats inventing a questionnaire. It also beats sending all 261 questions to a four-person vendor, which produces a spreadsheet nobody reads. The failure mode there is the one in recommendation before diagnosis.

A proportionate process

For a company without a procurement function, this is the version that fits on one page.

  1. Write down what you are actually sharing, before the kickoff call. Most teams discover here that the answer is more than they thought.
  2. Ask the five ownership questions. Get the model-training answer in the contract.
  3. Ask for the access list and the subcontractor list. Set a date to re-request both.
  4. Agree the exit terms while everyone is still pleased with each other.
  5. Put a single named person on your side in charge of the shared surface. Not a committee, not the vendor.
  6. Diary a ninety-day access review. Remove what the project no longer needs.

Step six is where the value is and it takes twenty minutes. Access sprawl in a shared workspace is the most reliably present and most reliably ignored finding in collaborative work.

At Kief Studio we run this the way we run everything else, which is by holding the infrastructure rather than coordinating across four vendors who each hold a piece. That model is described at ltfi.ai, and the cost argument behind it is IT platform consolidation cost savings versus claims. Our dependency tooling is public at kief.dev, including the Vekt lockfile scanner and ks-aur-scanner. Brian Gagne owns the security architecture side, at briansgagne.com.

Related reading

Frequently Asked Questions

What should I ask a vendor about protecting proprietary data in a collaborative project?

Ask who owns the output and the intermediate artifacts, whether your material trains any model, how the shared workspace is isolated, which subcontractors touch it, and what happens to every copy at exit. Get the model-training answer in the contract rather than in email.

Does an NDA cover this?

Partially. Most NDAs cover disclosure and say little about derived work, aggregates, model training, access management, or retention. Those are the five places proprietary value actually moves, so they need their own terms.

What is the single highest-value question?

"Can you produce the current list of everyone on your side with access to our shared workspace, today?" The speed of the answer tells you whether access is managed or merely granted.

Should a small company send a 261-question CAIQ?

Usually not. CAIQ-Lite covers all 17 domains in 124 questions and is proportionate for early screening. Reserve the full questionnaire for vendors holding regulated or genuinely sensitive material.

How often should access to a shared workspace be reviewed?

Every ninety days during an active engagement, and once at closeout with written confirmation. Collaboration accounts are created quickly and removed slowly, so the review is the control.

Cybersecurity Sep 15, 2026 7 min

Vendor Security Questions for Mixed Data Environments

Vendor security protocol questions for mixed data environments come down to who owns each control across your estate and theirs. CSA added Shared Security Responsibility Model columns to CAIQ v4 because unassigned controls are a leading source of cloud risk.

Operations Sep 13, 2026 8 min

Cybersecurity Questions for 401(k) Technology Vendors

Cybersecurity questions for 401(k) technology vendors start with the DOL's six hiring tips. Since Compliance Assistance Release 2024-01 they cover health and welfare plans too, and EBSA named cybersecurity a FY2026 national enforcement project.

Entrepreneurship Sep 8, 2026 4 min

Partner Vetting Questions Founders Skip

Partner vetting at mid-market is operational due diligence, not an M&A room. CISA Secure by Demand (6 Aug 2024) plus registrar, restore date, and named operator. Four shrugs is a no.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe