The questions a security review actually asks

Grouped by who tends to ask them. Every answer concedes the limit where one exists — what a KMS outage does to a running workflow, what survives a deletion in backups, and which DPDP obligations stay yours no matter what we build.

Eight categories. The order follows how a review tends to run: architecture first, then the AI behaviour, then the paperwork.

Security

AI approvals

Compliance

Integrations

Data residency

Pricing

Enterprise support

Migration

What next

Still unanswered

If your reviewer needs more than this page carries, the architecture document and subprocessor register are available before you sign anything, and a sandbox tenant lets them test the controls rather than read about them.