About usCareersCase studiesPricingBook a demoLog in
Security

13 questions to ask before you trust an AI tool

Most questions I get asked about Marloo come down to two things: where the data sits, and who can access it. Both are fair starting points. Neither, on its own, tells you much.

15 July 2026
Sacha Lala

Sacha Lala

Security & Compliance Lead, Marloo

Sacha spent years assessing organisational risk and cybersecurity controls at EY and Arm before joining Marloo. Having sat on both the external consulting and internal GRC sides of the table, she brings an auditor's eye to what actually matters in AI and third-party tools.

This is the conversation I want every adviser to have before they sign up to any AI tool. Not just Marloo. Any AI tool. Because the easiest way to get caught out when choosing a vendor is to ask the wrong question and walk away reassured by an answer that didn't really cover what you needed to know. Previously, I've spent time on the other side of the equation, assessing third-party AI tools, and deciding whether to onboard them. I've learnt what is important to look out for.

What follows is the framework I'd use if I were sitting where you are. A short primer on how AI tools actually handle data, and then thirteen questions I'd put to any vendor I was considering. I've included how we answer each one at Marloo, so you can see what good looks like and use the same bar with anyone else you evaluate.

A quick primer: how data actually moves through an AI tool

The single most common misunderstanding I come across is the idea that “where my data is stored” is the same as “where my data is processed.” It isn't, and conflating the two leads to incorrect conclusions.

Every modern AI tool you'll evaluate works by combining specialist services. One service captures the meeting. Another converts the audio to text. Another generates the summary or file note. Another stores the final result in a database. These are called sub-processors, and they exist in every cloud-based software product you already use, including your CRM, your email, your document storage, and your calendar. You may not always be informed about them, but they exist.

The right questions are sharper: which ones, under what contracts, and with what protections? Some sub-processors store data for the long term (your primary database, for example). Most don't. The strongest AI vendors operate under what's called zero data retention with their LLM providers, which means a prompt goes out, an answer comes back, and the provider keeps nothing. Nothing stored, nothing logged, nothing used to train AI models. That's a contractual obligation, not a marketing promise.

For Marloo customers in the UK, the picture looks like this:

How data moves through Marloo: UK customer meeting, then Recall AI, AssemblyAI, Anthropic or OpenAI, and Supabase London plus AWS London
  • Stage 1: Recall AI (Europe) joins the meeting (recordings deleted immediately after processing).
  • Stage 2: AssemblyAI (Europe) transcribes the audio (deleted after processing).
  • Stage 3: Anthropic and OpenAI generate the summary (zero data retention; nothing kept).
  • Stage 4: Supabase London stores the final file note and unified client record. Daily encrypted backups held in AWS London.

With that in mind, here are the questions worth asking, and what good answers look like.

Questions & Answers

This is the easiest question to ask and the easiest one for a vendor to be vague about. A good answer is specific: it names the region, the infrastructure provider, and where backups sit.

How we answer at Marloo: Primary customer data for UK firms is stored in the United Kingdom, on Supabase infrastructure hosted in AWS London. Daily encrypted backups are held in AWS London, in the same region.

Sub-processors are not a red flag. Hidden sub-processors are. Any vendor serious about security publishes their full list and updates it when it changes. If a vendor can't tell you who else touches your data, that tells you everything you need to know.

How we answer at Marloo: Our full sub-processor list is published at trust.marloo.com/sub-processors. The four high-sensitivity sub-processors are:

  • Recall AI (meeting capture) — Europe. Deleted immediately after processing.
  • AssemblyAI (transcription) — Europe. Deleted immediately after processing.
  • Anthropic and OpenAI (LLM processing) — USA. Enterprise zero data retention.
  • Supabase (storage) — UK. Primary storage.

Each one has a defined role and a contractual relationship with us that governs what they can and can't do with the data. We choose the most suitable processing location for each provider based on where our customers are. When a provider opens up a region closer to our customer base, we move, as we did with Recall AI and AssemblyAI when they launched European processing.

Some AI processing genuinely does need to cross borders. The largest LLM providers (Anthropic and OpenAI) host their infrastructure in the United States. That's not a problem in itself, provided the legal mechanism covering the transfer is in place. The wrong answer here is "we don't transfer data anywhere," because almost no AI tool can honestly say that. The right answer is a clear statement of which mechanism applies.

How we answer at Marloo: Primary UK customer data is stored in the UK. As set out in the sub-processor list above, the only step that crosses the UK border is LLM processing (Anthropic and OpenAI) in the United States, under enterprise zero data retention. That transfer is covered by the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses. We rely on adequacy decisions where one applies, and on other appropriate safeguards under Article 46 UK GDPR where applicable. Marloo acts as a processor on behalf of the customer (who is the controller), in line with Article 28 UK GDPR. Marloo is registered with the UK Information Commissioner's Office.

This is the question I'd ask first if I were evaluating an AI tool. A vendor that uses your client data to train their own models, or allows their LLM providers to do so, is a vendor whose interests are no longer aligned with yours. The answer should be no. It should be in writing. And it should cover both proprietary models and any third-party models the vendor uses.

How we answer at Marloo: No. Marloo does not use customer data to train any language models, proprietary or third-party. This is contractually guaranteed by every LLM vendor in our pipeline, not just stated in our marketing. Customer data remains isolated to the customer's environment. Customers own all templates, transcripts, summaries, and file notes generated through Marloo. We retain only the limited right to process that data in order to deliver the service.

For regulated firms, this matters more than it might seem. If a file note or suitability report is generated by an AI tool, you need to be able to demonstrate, after the fact, how that output came to exist. That's an audit trail question, and not every vendor can answer it.

How we answer at Marloo: Yes. We maintain comprehensive audit trails and logs that allow firms to trace how file notes and other AI-generated outputs were produced. This is part of our SOC 2 Type 2 control set. Security logs are retained for 15 months; access logs for a minimum of one year and reviewed regularly.

This should be a short, specific answer. Encryption standards are well-established, and any vendor handling client data should be using current ones. If the answer is vague, that's a signal.

How we answer at Marloo: AES-256 encryption at rest, TLS 1.2 or higher in transit (TLS 1.3 preferred). Daily encrypted backups. API requests authenticated with JSON Web Tokens signed by Marloo's Auth service. Row-Level Security enforced at the database row level on every table, which means even if someone managed to get past the application layer, the database itself enforces that one customer cannot see another customer's data.

It is not enough that your data is encrypted. You need to know who at the vendor can decrypt it, under what circumstances, and what stops them from doing so casually. The strongest vendors will be specific: role-based access, mandatory multi-factor authentication, least privilege, and regular access reviews.

How we answer at Marloo: Access to core customer data and production infrastructure is restricted to essential staff only, under least-privilege policies. We enforce role-based access control across all supporting platforms, with mandatory multi-factor authentication on every access point. Admin privileges are restricted. Access is granted on a role basis and removed on role change or departure. Quarterly access reviews form part of our SOC 2 Type 2 control set.

A vendor that can't tell you cleanly what happens when the relationship ends is a vendor you shouldn't enter the relationship with in the first place. You want to hear two things: that working copies are deleted promptly, and that any retained backups have a defined limit.

How we answer at Marloo: While your account is active, your data stays available to you (advisers tend to revisit recordings and notes frequently, and our AI uses that history to produce better drafts). Web app recordings, transcripts, summaries, and file notes are retained while the account is active, unless manually deleted. We're rolling out more granular customer-side deletion controls in the near term. When an account ends, you can instruct us to delete or export all data. We then delete working copies promptly and retain one encrypted legal-backup copy for up to seven years, unless you request a shorter hold. Specific earlier deletions are available on request to support@marloo.com.

SOC 2 Type 2 is the most common independent security certification for software vendors handling sensitive data. It's not the only meaningful one, but its absence in this category should give you pause. The certification has to be independently audited, and the audits are annual.

How we answer at Marloo: Yes, currently held. The certificate and live controls are available in our Trust Centre at trust.marloo.com. We're currently in the audit observation period for our next cycle. The full report is available under NDA on request.

This one separates the serious vendors from the ones who write polished marketing copy. A penetration test is a paid engagement with independent security professionals who actively try to break the platform and write up what they found. The right answer includes a recent date and an offer to share the report.

How we answer at Marloo: Marloo has undergone two independent penetration tests in the last six months: one completed in October 2025, the second in April 2026. Two pen tests in six months is well ahead of industry norms for a company at our stage, and reflects how seriously we take this. Executive summaries are available under NDA on request.

Beyond formal certifications, several independent organisations rate vendors on their overall cyber maturity. These ratings give you a comparative read on how a vendor sits relative to the broader market.

How we answer at Marloo: Marloo holds a "Very Good" rating from Aphore's Cyber Assurance Risk Rating (CARR), a globally recognised benchmark of cyber maturity and resilience. That rating places us in the same category as Microsoft Copilot. We also engage independent third parties to test our incident response and business continuity plans through synthetic red team exercises.

Every vendor will eventually face an incident of some kind. What matters is how quickly and clearly they tell you when it affects your data. The answer you want is a specific timeframe (the UK GDPR standard is 72 hours), and a clear scope of what gets communicated.

How we answer at Marloo: In the event of a breach, we notify affected customers within 72 hours of becoming aware of it, as required by UK GDPR Article 33. You'll get a description of the incident and its status, the data categories affected (and volumes where known), what we've done to contain and remediate it, what we recommend you do, a point of contact, and ongoing updates as the investigation develops. This is set out in Clause 9 of our DPA.

Combining these because they're both contractual checks that often get skipped. A DPA is the legal document that defines what the vendor is and isn't allowed to do with your data. It should be a standard part of the terms, not something you have to negotiate from scratch. Insurance matters because it tells you whether the vendor has the financial resilience to actually meet its obligations if something does go wrong.

How we answer at Marloo: Our standard Data Processing Agreement is Schedule 1 to our Terms of Service at marloo.com/terms. It forms part of our contract with every customer. On insurance: Marloo carries a Technology Professional Indemnity and Cyber policy with substantial aggregate cover for professional liability, cyber liability and privacy, and a dedicated limit for cyber incident response. We also carry a Corporate Directors and Officers Liability policy. Territorial scope of both policies is worldwide. Full policy details are available on request.

The bigger picture

If you've followed me to this point, you'll have noticed something. The question of where your data is stored is one of thirteen. It's an important one, but it is one of thirteen. Some of the most important things to ask a vendor have nothing to do with geography. Encryption standards, access controls, penetration testing, breach commitments, contractual safeguards, insurance: these are the things that determine whether your client information is actually safe, not just where it happens to sit on a map.

The vendors worth working with will give you specific, confident answers across all thirteen, because transparency is how trust gets built in this space. If the answers get vague, or the conversation keeps drifting back to the same one or two strengths, that's worth noticing.

We've built Marloo's security and compliance programme to give straight answers to every question on this list, because that's the standard regulated firms deserve and the standard your clients trust you to apply. If you ask me a question I haven't covered here, I'll give you the same kind of answer, in writing, with the supporting source.

Sacha Lala

Sacha Lala

Sacha is the Security and Compliance Lead at Marloo. She works with UK advice firms on vendor due diligence, security questionnaires, and the compliance questions that come with using AI in regulated environments.

Your calling is advice,
not admin

Set up in minutes. Start with your next meeting, completely free.

Start with your next meeting
See it in action