The questions a security review actually asks
Grouped by who tends to ask them. Every answer concedes the limit where one exists — what a KMS outage does to a running workflow, what survives a deletion in backups, and which DPDP obligations stay yours no matter what we build.
Eight categories. The order follows how a review tends to run: architecture first, then the AI behaviour, then the paperwork.
Security
AI approvals
Compliance
Integrations
Data residency
Pricing
Enterprise support
Migration
What next
Still unanswered
If your reviewer needs more than this page carries, the architecture document and subprocessor register are available before you sign anything, and a sandbox tenant lets them test the controls rather than read about them.