Blog

What to ask an AI support vendor about your data when you don't have a security team

Buying an AI agent means reading a page of acronyms with nobody in the building to translate them. Most of it is ordinary software hygiene you already know how to check. The new part is narrow: what the agent is allowed to say, and what it's allowed to reach.

Field notes · · 6 min read

Anchor AI

The security questions about an AI support agent split about ninety to ten. Ninety percent are the questions you’d ask any software that holds customer data: where is it, who can see it, can I get it deleted. Ten percent are genuinely new, and they’re the ones vendor pages tend to bury under certification logos. This post is the whole list, short, with how we answer it for Anchor— including the one answer that’s “not yet”.

The ninety percent: ordinary questions

These have crisp answers, or the vendor is hiding something.

QuestionA good answer sounds likeAnchor’s answer
Is data encrypted in transit and at rest?“Yes, both,” with no hedging.Yes: TLS in transit, encrypted at rest.
Who inside the company can see my customers’ conversations?A small set, with access logged.Internal production access is limited and logged; workspaces are isolated from each other.
Can I have it deleted?A process, a contact, and a retention period for backups.Yes, on request to info@anchorai.chat; backups are kept for a limited period, then purged.
Where do card details go?Never through the vendor.Payments run through Paystack; card details never touch Anchor’s systems.
What law governs my data?A named act and a named jurisdiction.Ghana’s Data Protection Act, 2012 (Act 843), and the GDPR where it applies.
Who can do what in my workspace?Roles with real differences.Three roles — owner, admin, agent — enforced on the server, not just hidden in the interface.

Every line of that is in our privacy policy and terms, which is the other test: a vendor’s answers should be written down somewhere a lawyer can read, not just said on a call.

The ten percent: what’s new with an agent

Two questions have no equivalent in the software you’ve bought before, because the software you’ve bought before didn’t talk to your customers on its own.

What is it allowed to say?

An ungrounded model answers from everything it absorbed while being trained, which means it can state your return window confidently and wrongly, because it has never read your return window. Ask the vendor: where does an answer come from, and what happens when the answer isn’t in my content?

The good answer has two parts. Answers come only from the content you connected, and you can see which document each one came from. And when the content doesn’t cover it, the agent says so and hands the conversation to a person rather than filling the silence. Anchor is built on exactly that rule — the homepageshows the difference on one question, and the “invented” side is the more common product.

What is it allowed to reach?

The second new question is access. An agent that can look up an order, or trigger a refund, is more useful than one that can’t — and more dangerous, because now the question is what it can do, not just what it can say. Ask: what systems can the agent touch, who decides, and is there a log?

In Anchor the answer is nothing by default. The agent reaches an external system only through an action you defined: a connection you set up, an endpoint you named, parameters you typed, and an audit log of every call it made with the status that came back. Adding a capability is a deliberate act by an admin, not a permission the agent grants itself.

Does my data train the model?

Ask it directly, because the honest answer is a sentence and the dishonest one is a paragraph. Anchor’s: your content and your customers’ conversations are not used to train shared models, and the model providers we use are under contracts that prohibit it too.

On certifications

Certifications are worth exactly what’s behind them: a named auditor, a report, and a date. SOC 2 is a report an audit firm either issued or didn’t. “GDPR compliant” is a posture with a paper trail. Neither is a badge a website can award itself, and you’ll see plenty that try.

Our own position: Anchor doesn’t hold a SOC 2 report today, and we don’t claim one.When we do, the date will be on the page. Until then the list above is the list — the controls that are implemented — and nothing more. If a vendor of any size can’t produce the report behind the logo, treat the logo as decoration.

Where to focus

Confirm the ordinary six in writing. Then ask the two new questions and listen for the shape of the answer: “only from your content, and it hands off when it can’t” for the first; “nothing by default, and here’s the log” for the second. A vendor that answers both plainly has thought about the problem. One that answers with a certification page hasn’t understood which part of the problem is new.

Common questions

Is my customer data safe with an AI support agent?

It depends on ordinary things you can check — encryption in transit and at rest, who can see it internally, deletion on request, which law governs it — and two new ones: what the agent is allowed to say and what it can reach. Anchor answers only from your own content, reaches external systems only through actions an admin defined, and never uses your data to train shared models.

Does Anchor use my data to train AI models?

No. Your content and conversations are not used to train shared models, and the model providers Anchor uses are under contracts that prohibit training on them as well. Data is encrypted in transit and at rest and purged on request.

Is Anchor SOC 2 certified?

Not today, and we don't claim it. Anchor lists the controls that are actually implemented — encryption, role-based access, isolated workspaces, no training on customer data, deletion on request — and will put a date on a certification when there's a report behind it.

Can an AI support agent access my other systems?

Only if you connect them. In Anchor the agent has no access by default; it reaches an external system only through an action an admin defined — connection, endpoint, parameters — and every call is written to an audit log with its status.

← All posts

Published

See it answer from your own content

Point Anchor at your help center and watch it answer your real questions — 30 days free, no card.