"Who sees our customer data?" Four answers. One survives an auditor.
SCHEDULE · THE SUB-PROCESSOR QUESTION · SECURITY QUESTIONNAIRES

General notes
- 01Procurement asks this on every serious deal now. Engineering teams give one of four answers.
- 02Only A holds under questioning. D holds only if you can show the log.
Schedule of answersWhat each one sounds like to the auditor
| Ref | Answer | What the auditor hears |
|---|---|---|
| A | The model provider is listed, with what it receives | Someone did the work |
| B | The provider is listed, but not what it receives | The list exists. The evidence does not. |
| C | It is not on the list yet | Honest. Also the most common. |
| D | We strip personal data before it leaves | Show me the log |
As posted
"Which sub-processors see our customer data?"
Procurement asks it on every serious deal now, and every engineering team gives one of four answers. I have heard all four from teams shipping AI features on top of real customer data.
A. The model provider is listed, with exactly what it receives. B. The provider is listed, but nobody can say what it receives. C. It is not on the list yet. D. We strip personal data before it leaves, so it does not need to be.
Only A holds under questioning. B means the list exists and the evidence does not, which an auditor notices in about a minute. C is the most common answer and the most honest one. D holds only if you can produce the log proving the stripping happened before the request left.
This is not a legal formality. It is a boundary question. Your prompt leaves your infrastructure and lands in someone else's, and the list is how you admit that in writing.
If the answer cannot be written down today, that is the work. It is smaller than it looks, and it gets much bigger the week a customer's security team asks first.
Sheet 005.