AI vendor risk assessment: questions and where to look
An AI vendor risk assessment adds training, model providers and spend to a SaaS review. The questions, and where Sume's public pages answer them.

An AI vendor risk assessment asks the questions of any SaaS security review, such as data location, retention, deletion, subprocessors, access control and availability, plus a few that AI tools raise: whether your inputs train models, which model providers see them, and who can spend money on your account. Answer each one from the vendor's own terms, privacy policy and docs, and treat "not published" as an answer to follow up in writing.
The Sume answers below come from its Terms of Service (last updated August 10, 2026), its Privacy Policy (last updated September 13, 2026) and the docs, read on 2026-09-29. For an API capability review instead, see the 12-point API checklist. None of this is legal or compliance advice.
What questions should an AI vendor risk assessment ask?
Group the questionnaire by what could go wrong:
- Data use: does the vendor claim a license over your content, and does it cover training?
- Data flow: which subprocessors and model providers receive your data, and in which countries?
- Retention and deletion: how long inputs and outputs are kept, and how you get them removed.
- Access: how credentials are scoped and revoked, who in your team sees what, and who can open outputs.
- Spend: what stops an agent, a script or a leaked key from running up a bill.
- Commitments: uptime, support and contract terms, and which document controls when they differ.
How do Sume's public pages answer them?
Row by row, with the page to cite in your assessment:
| Question | What the page says | Page |
|---|---|---|
| Is our content used to train models? | You keep ownership; Sume gets rights to use it "to provide, secure, support, and improve the Services". Training is not addressed either way | Terms |
| Who processes our data? | Named providers include Clerk, Vercel, Stripe, PostHog, Vercel Analytics and Sentry. AI model providers are listed by category, not by name, and model routing is kept private | Privacy Policy, Terms |
| Where is data stored? | The United States and other countries where Sume or its service providers operate | Privacy Policy |
| How long is data kept? | As long as needed for listed purposes; periods vary by type of data | Privacy Policy |
| How do we get data deleted? | Email request to dev@sume.com; deletion is not a promise of immediate removal from every backup or provider's systems | Privacy Policy |
| How is data protected? | Safeguards "including access controls and encryption in transit" | Privacy Policy |
| Are generated files private? | A Format run's artifact URLs are durable, and a durable URL is public: anyone who has it can fetch it | Embed a Format |
| How are API credentials scoped? | Keys are workspace-scoped, the full secret is shown only at creation, scopes are fixed when a key is created, and keys are revoked from the dashboard | API keys, Authentication |
| What availability is committed? | Provided "as is" and "as available"; no guarantee of uninterrupted availability | Terms |
Who can spend money on our account?
Ask which setting authorizes spend, and what it is by default. Sume's Terms say the spend approval mode you select, and any threshold you set, is your authorization for the resulting spend, including by scheduled runs and automations. In current code the default mode for new Agents threads is "Run without asking", so record the setting your team will use before anyone runs unattended work.
A leaked key is an access question and a spend question at once: revoke it from the dashboard. The approval modes and the per-run Format cap are covered in AI video generator for business.
What does Sume not publish?
Record these as gaps, not as answers. The Terms, the Privacy Policy and the docs read for this post don't mention a SOC 2 or ISO report, a data processing agreement, an uptime SLA, a standalone subprocessor list, a choice of data location, or encryption at rest.
The Terms say enterprise services may be governed by an Order Form or other written agreement, which controls where its commercial terms conflict with the Terms. Ask your open questions in writing before you sign. API uptime SLA covers the availability question in more depth.
Sources
Related posts
More in Developers
- API sandbox environment: test a paid API without paying
An API sandbox is a separate test environment with fake or free results. Sume has none, so test with its spec, free checks and spend caps.
- API throttling vs rate limiting: what's the difference?
Rate limiting refuses requests over a quota with a 429; throttling slows or queues the excess instead. What each one means for your client.
- Automate video editing in Python with an editing API
Automate video editing in Python by calling an editing API with Requests: submit a caption, cut, or crop job, poll until it ends, chain the output.
- Bash for loop with curl: one API request per line
Loop over a file with while IFS= read -r, build each JSON body with jq --arg, send it with curl --fail-with-body, and pace it under the API's rate limit.
Written by Sume