1 min lesson
Security, privacy & enterprise-readiness basics
Explain the practical point behind "Security and Legal are what kill it at the one-yard line."
Step 1 of 4
Developer love gets the deal to the table. Security and Legal are what kill it at the one-yard line. The AE who surfaces these questions early in discovery, instead of discovering them in week six, is the one who actually closes.
You won't be the expert on data policies and you don't have to be. You have to recognize the standard asks, give an honest high-level answer and route the specifics to the right resource without losing momentum.
Learn more
Advanced table
These four come up in nearly every commercial deal
- The question
- What gets sent to the models?
- What they're really worried about
- Their proprietary code leaving their control.
- How you handle it
- Explain at a high level what's processed, then route specifics to a security resource.
- The question
- Is our code used to train models?
- What they're really worried about
- Their IP becoming someone else's model.
- How you handle it
- Know there are privacy / no-training modes; speak to them honestly and confirm details.
- The question
- What's your data retention?
- What they're really worried about
- How long anything sits and where.
- How you handle it
- Acknowledge it's a real requirement and bring the documented policy, don't improvise.
- The question
- Are you SOC 2 compliant?
- What they're really worried about
- A checkbox their security team requires.
- How you handle it
- Know the compliance posture exists; have the report request path ready.
| The question | What they're really worried about | How you handle it |
|---|---|---|
| What gets sent to the models? | Their proprietary code leaving their control. | Explain at a high level what's processed, then route specifics to a security resource. |
| Is our code used to train models? | Their IP becoming someone else's model. | Know there are privacy / no-training modes; speak to them honestly and confirm details. |
| What's your data retention? | How long anything sits and where. | Acknowledge it's a real requirement and bring the documented policy, don't improvise. |
| Are you SOC 2 compliant? | A checkbox their security team requires. | Know the compliance posture exists; have the report request path ready. |
These four come up in nearly every commercial deal. Recognizing them is half the battle.