What's inside
Seven categories, in the order a real evaluation tends to move: where the data lives, what happens to it, who can see it, how it's protected, what a lawyer still has to verify, what's actually in the contract, and who else has already lived with the answers.
Data Residency & Storage
Named regions, not country names; subprocessors; backups; Quebec Law 25 privacy impact assessment triggers; PHIPA touchpoints when health information is involved.
Training-Use & Retention Terms
Whether inputs and outputs train the model, a specific retention window, the difference between “no training” and “zero retention,” and what happens to data after you leave.
Confidentiality & Privilege
Who can access raw client content, how privileged material is treated, audit trails, compelled-disclosure exposure, and integration access scope.
Security Posture
Encryption standards by name, the honest status of any third-party attestation, breach-notification terms, testing cadence, and internal access controls — without assuming a certification is required.
Supervision & Output Verification
What the vendor says about its own reliability, citation grounding for research tools, audit history, and precisely which actions the tool can complete without a human's approval.
Contract Terms & Exit
Data export before you sign, a defined post-termination deletion date, work-product ownership, and notice periods for unilateral changes.
References
What a comparable Canadian firm's own evaluation actually found, and whether the vendor's story stayed consistent.
Each of the 32 items is one checkable sentence plus a short “why it matters” note — built to hand to whoever runs your firm's next vendor call, print for a partners' meeting, or work through line by line before you sign anything. Prefer to read it online first? The full checklist is also live as a page on this site.