| Where is our data stored? | Our provider is a major cloud with Australian operations | Named service, Australian region, verified on a stated date | Coverage is per service, and where it is stored is not where it is processed. |
| Can a foreign government access it? | No, it is stored in Australia | Ownership, jurisdiction and the residual risk stated | The wrong answer here is the one most likely to unravel later. Name the limit. |
| Do they train on our content? | Their website says they do not | Clause cited from the agreement, carve outs noted | Marketing pages change without notice. The addendum is what an auditor reads. |
| Is this sovereign AI? | Yes, it runs in Australia | No. It is Australian residency, and here is why that differs | Answering yes to this invites the follow up question you cannot answer. |
| Who can see the outputs? | Only authorised users | Identity groups named, permission test described | A described test beats an assertion, because the reviewer can picture repeating it. |
| How long is data retained? | Per the vendor default | Configured value, plus audit log retention window | Defaults suit the product, not your disposal schedule. Some default to indefinite. |
| What if we want to leave? | We would migrate | What we own, what we would rebuild, rough cost | The question sovereignty language is usually really asking. Answer it directly. |
| What could go wrong? | Nothing, it is enterprise grade | Named failure modes and the controls for each | A vendor who names risks is more credible than one who claims there are none. |