Most questions I get asked about Marloo come down to two things: where the data sits, and who can access it. Both are fair starting points. Neither, on its own, tells you much.
Sacha Lala
Security & Compliance Lead, Marloo
Sacha spent years assessing organisational risk and cybersecurity controls at EY and Arm before joining Marloo. Having sat on both the external consulting and internal GRC sides of the table, she brings an auditor's eye to what actually matters in AI and third-party tools.
This is the conversation I want every adviser to have before they sign up to any AI tool. Not just Marloo. Any AI tool. Because the easiest way to get caught out when choosing a vendor is to ask the wrong question and walk away reassured by an answer that didn't really cover what you needed to know. Previously, I've spent time on the other side of the equation, assessing third-party AI tools, and deciding whether to onboard them. I've learnt what is important to look out for.
What follows is the framework I'd use if I were sitting where you are. A short primer on how AI tools actually handle data, and then thirteen questions I'd put to any vendor I was considering. I've included how we answer each one at Marloo, so you can see what good looks like and use the same bar with anyone else you evaluate.
The single most common misunderstanding I come across is the idea that “where my data is stored” is the same as “where my data is processed.” It isn't, and conflating the two leads to incorrect conclusions.
Every modern AI tool you'll evaluate works by combining specialist services. One service captures the meeting. Another converts the audio to text. Another generates the summary or file note. Another stores the final result in a database. These are called sub-processors, and they exist in every cloud-based software product you already use, including your CRM, your email, your document storage, and your calendar. You may not always be informed about them, but they exist.
The right questions are sharper: which ones, under what contracts, and with what protections? Some sub-processors store data for the long term (your primary database, for example). Most don't. The strongest AI vendors operate under what's called zero data retention with their LLM providers, which means a prompt goes out, an answer comes back, and the provider keeps nothing. Nothing stored, nothing logged, nothing used to train AI models. That's a contractual obligation, not a marketing promise.
For Marloo customers in the UK, the picture looks like this:
With that in mind, here are the questions worth asking, and what good answers look like.
If you've followed me to this point, you'll have noticed something. The question of where your data is stored is one of thirteen. It's an important one, but it is one of thirteen. Some of the most important things to ask a vendor have nothing to do with geography. Encryption standards, access controls, penetration testing, breach commitments, contractual safeguards, insurance: these are the things that determine whether your client information is actually safe, not just where it happens to sit on a map.
The vendors worth working with will give you specific, confident answers across all thirteen, because transparency is how trust gets built in this space. If the answers get vague, or the conversation keeps drifting back to the same one or two strengths, that's worth noticing.
We've built Marloo's security and compliance programme to give straight answers to every question on this list, because that's the standard regulated firms deserve and the standard your clients trust you to apply. If you ask me a question I haven't covered here, I'll give you the same kind of answer, in writing, with the supporting source.
Sacha Lala
Sacha is the Security and Compliance Lead at Marloo. She works with UK advice firms on vendor due diligence, security questionnaires, and the compliance questions that come with using AI in regulated environments.
Marloo Trust Centre
Live controls, certifications, our sub-processor list, and the full SOC 2 Type 2 certificate — everything in one place.
Privacy Policy
How Marloo collects, uses, and protects personal data.
Data Processing Agreement
Schedule 1 to our Terms of Service — the legal document that governs how we handle your data.
Get in touch
For any privacy or security questions, email compliance@marloo.com.
Set up in minutes. Start with your next meeting, completely free.
Start with your next meetingSee it in action© 2026 Marloo. All rights reserved.