Private is a marketing word. It has no agreed technical meaning, no certification behind it, and nothing stops anyone from using it. We use it ourselves, which is exactly why we think you should know how to test it.
Here are the seven questions we would put to any AI vendor in India, including us, and what a real answer sounds like as opposed to a reassuring one.
1. Where is my data processed, and in which country?
A vague answer here predicts vague answers everywhere else. You want a named provider, a named region, and whether anything crosses a border.
What good sounds like: your files are stored in our account in the Mumbai region, questions are sent to a named model provider under an enterprise agreement with zero-retention terms, and here is the clause.
What to be wary of: "it is fully secure and encrypted." Encryption is about interception. It says nothing about who has access at the other end.
2. Is my data used to train anyone's model?
This is the question most people mean when they say private. Get it answered about three parties, not one: the vendor, the model provider, and any tool in between.
Consumer AI subscriptions and business ones often differ here, and the difference is not obvious from the interface. A vendor who has not read their own model provider's enterprise terms cannot answer this, and their confidence is worth nothing.
3. How long is my data retained after the answer is returned?
Ask for a number in days, and ask what happens to logs. Many systems that do not train on your data still keep prompts for abuse monitoring for a period. That may be perfectly acceptable to you. Not knowing is what is not acceptable.
4. Who at your company can see my data, and what stops them?
Every vendor has engineers who can technically reach production. The honest answer is not "nobody", it is a description of the control: access is limited to two named people, it is logged, it requires a ticket, and it is covered by the NDA.
A vendor claiming literally nobody can ever see anything is either running an architecture they should be able to describe in one sentence, or they have not thought about it.
5. Under the DPDP Act, which of us is the Data Fiduciary?
This is the question that separates people who have read the law from people who have heard of it.
India's Digital Personal Data Protection Act, 2023 and the rules notified under it in 2025 set up two roles. The Data Fiduciary decides why and how personal data is processed and carries the legal obligations. The Data Processor handles it on the Fiduciary's instructions, under contract.
In almost every AI engagement, you are the Fiduciary and the vendor is the Processor. That matters more than it sounds, because it means the notice, consent and breach-reporting duties are yours. A vendor cannot take them off you, and one who implies they can is selling comfort.
Two things follow that are worth knowing. First, the obligations are phased: the rules were notified in November 2025 with the substantive compliance requirements phased in over eighteen months, with the bulk landing in 2027. Second, the penalties are large enough to be a board matter, running up to ₹250 crore for a failure to take reasonable security safeguards.
There is also a trap on the other side. If a vendor trains a model on your customer data, they are no longer merely processing on your instructions, and both of you have a problem. This is a further reason the training question is not academic.
None of this is legal advice, and it is worth a conversation with your own counsel. But the question is a very good sorting mechanism.
The point of publishing a test is that it should be possible to fail it. Ours is above. Use it on us.
6. Can I see, export and delete everything?
Ask what happens on the day you leave. Does your data come back to you in a usable format, is it deleted from their systems, and will they confirm that in writing.
The version of this question that reveals the most: can I get my data out without asking you? Systems designed for exit are designed by people who expect to be judged on merit.
7. Can I check the answers?
People rarely think of this as a security question, but it is the same family. A system that cites the file, the row and the document it drew from is auditable. One that produces a confident paragraph from nowhere cannot be checked by you, your auditor, or a regulator asking how a decision was made.
Verifiability is what turns a plausible answer into evidence. We argue this at length in an answer you cannot check is worse than no answer.
What we mean by it, since we use the word
For us, private means four specific things, and we would rather be held to these than to the adjective.
What we commit to
- Your data is stored in infrastructure dedicated to you, in India, not pooled with other clients.
- Nothing you give us is used to train any model, ours or anyone else's, ever.
- Model providers are used under enterprise terms with zero-retention, and we will show you the clause.
- Every answer cites its source, so you can verify it rather than trust it.
If another vendor gives you better answers to the seven questions above, go with them. The point of publishing the test is that it should be possible to fail it.
Our full position is on the data security page, and you are welcome to send it to your IT team to pick apart.

