shield_lockSecurity

AI Data Security and Privacy: What to Ask Before You Deploy

Training use, retention, encryption, access control, and compliance — the questions to settle before an AI agent touches customer data, and what good answers look like.

schedule7 min readupdateUpdated September 11, 2026
Quick answer

How do you keep data secure and private when deploying AI agents?

Before deploying an AI agent, establish in writing whether your data trains the vendor's models, how long transcripts and recordings are retained, how data is encrypted in transit and at rest, who can access it, and how export and deletion work. Nexivo encrypts data in transit and at rest, never sells it, never uses it to train public models, and supports export or deletion at any time.

keyKey takeaways

  • check_circleTraining use is the first question: data used to train a shared model cannot be meaningfully recalled later.
  • check_circleRetention is a risk multiplier — data you no longer hold cannot be breached, subpoenaed, or leaked.
  • check_circleApply minimum necessary as a design constraint: give the agent only the fields the task requires.
  • check_circleAccess control matters on both sides — your team's roles and the vendor's internal access to your data.
  • check_circleGet compliance claims as artifacts: a SOC 2 report, a signed BAA, a DPA — not adjectives on a marketing page.

Does your data train their model?

This is the question to ask first, because it is the only one that cannot be undone. Data used to train a shared model is absorbed into weights that serve other customers. You cannot retrieve it, and deletion of the source record does not remove its influence.

Vendor answers fall into three categories. Some do not train on customer data at all. Some train by default with an opt-out, which means your data is in scope until someone remembers to change a setting. Some train on aggregated or de-identified data, and the important follow-up is exactly what de-identification means and who verified it.

The acceptable answer depends on your data. For a restaurant's booking calls the stakes are modest. For a law firm's client calls or a clinic's patient interactions, the only safe posture is no training use, stated in the contract rather than a support article. Nexivo does not use customer data to train public models.

Retention: the risk you can simply delete

Every recording, transcript, and log you keep is a liability with an indefinite tail. It can be breached, subpoenaed, or exposed by a misconfiguration years after anyone remembered it existed. Data you no longer hold carries none of that risk.

Most AI agent vendors default to keeping everything indefinitely, because storage is cheap and it is useful for debugging. That default serves the vendor, not you. Ask what the retention period actually is, whether you can configure it, and whether deletion means deleted or merely hidden from your dashboard while remaining in backups.

Set retention to the shortest period that meets your operational and legal needs. For most voice agent deployments, transcripts for 90 days and recordings for 30 covers quality review and dispute resolution. Longer needs a specific reason, and where you have a regulatory retention requirement, that requirement sets the floor — not the vendor's convenience.

Encryption, access, and the minimum-necessary rule

Encryption in transit and at rest is table stakes, and any vendor without both should be eliminated immediately. It is worth confirming rather than assuming, but it is not a differentiator.

Access control is where real differences appear. On your side, ask who in your organization can pull transcripts and recordings — that should be a defined role, not everyone with a login. On the vendor side, ask which of their employees can access your data, under what circumstances, whether that access is logged, and whether you can see those logs. 'Our engineers can access customer data for support purposes' is common and often acceptable, but you should know it rather than discover it.

Then apply minimum necessary as a design constraint rather than a policy document. An appointment-booking agent needs a name, contact details, and appointment type. It does not need the full customer record or the clinical chart. Every field you do not send is a field that cannot leak, and scoping integrations narrowly is the cheapest security control available.

  • Encryption in transit and at rest — confirm both explicitly.
  • Role-based access on your side; no blanket transcript access.
  • Documented and logged vendor-side access, visible to you.
  • Integration scoped to the fields the task genuinely requires.
  • Configurable retention, with deletion that removes data from backups too.

Compliance: ask for artifacts, not adjectives

Compliance claims on marketing pages are worth very little. What matters is whether the vendor can hand you the underlying document, and whether it covers the system you are actually buying.

For SOC 2, ask for the report — Type II, not Type I, since Type I only confirms controls existed on a single day while Type II tests that they operated over a period. Check the report's scope covers the product you are deploying rather than a different part of the vendor's infrastructure. Nexivo is SOC 2 Type II compliant.

For healthcare, you need a signed Business Associate Agreement before any protected health information reaches the system. For EU or UK personal data, you need a Data Processing Agreement naming sub-processors, and you should know which regions data is stored and processed in. A vendor who cannot produce these during evaluation will not produce them faster after you have signed.

Control over AI memory

Agents that remember across conversations introduce a category most security reviews miss. Persistent memory is what makes an assistant useful, and it is also a store of accumulated personal and commercial detail that sits outside your normal data inventory.

The requirements are straightforward: you should be able to see what the agent has remembered, correct it when it is wrong, export it, and delete it — all without contacting support. An agent whose memory you cannot inspect is an agent you cannot audit. Nexivo lets users export or delete their AI memory at any time.

Also consider memory scope in team deployments. One person's assistant should not surface another person's private context, and shared knowledge should be explicitly shared rather than accidentally pooled. Ask how memory is partitioned before rolling an assistant out beyond a single user.

Frequently asked questions

Does Nexivo use customer data to train AI models?

No. Nexivo encrypts data in transit and at rest, never sells customer data, and never uses it to train public models. Users can export or delete their AI memory at any time.

What is the first security question to ask an AI vendor?

Whether your data is used to train their models. It is the only decision that cannot be reversed — data absorbed into model weights cannot be retrieved, and deleting the source record does not remove its influence. Get the answer in the contract, not in a support article.

How long should AI call recordings and transcripts be retained?

The shortest period that meets your operational and legal needs. For many voice agent deployments, 90 days for transcripts and 30 days for recordings covers quality review and disputes. Regulatory requirements set the floor where they apply; vendor convenience should not.

Is SOC 2 Type II enough for an AI vendor?

It is a meaningful baseline because Type II tests that controls operated over a period rather than existing on one day, but ask for the actual report and check its scope covers the product you are deploying. Healthcare additionally requires a signed BAA, and EU or UK personal data requires a DPA naming sub-processors.

Can I delete what an AI assistant has remembered about me?

With Nexivo, yes — memory can be exported or deleted at any time. As a general evaluation criterion, you should be able to inspect, correct, export, and delete an agent's stored memory without filing a support request. Memory you cannot inspect is memory you cannot audit.

What does minimum necessary mean for AI integrations?

Give the agent only the data fields its task genuinely requires. A booking agent needs name, contact details, and appointment type — not the full customer record or clinical chart. Data that is never sent cannot be exposed, which makes narrow integration scoping the cheapest security control available.

Start tomorrow with
a 5-minute call.
Set it up today. Get your first briefing in the morning.
boltBook a demo