“Nothing sensitive goes in there”
People know not to put confidential material into it
It is a claim about people, not about the tool — and it is the one you can check.
This is the only one of the seven that is not a statement about a supplier. It is a statement about what colleagues do, and it is the only one here that can be settled from inside the organisation rather than by reading a contract. Settling it means finding the record of what was actually typed or pasted into the tool. Where no such record exists, the claim is a belief rather than a finding, which is not the same as saying it is wrong.
What to ask instead
Which record tells you what was actually pasted in last month?
This is the only one of the seven that is not about the supplier at all. It is a claim about what people in your own organisation do, and it is the one thing on this list you could go and check yourself.
If the answer is a European company you can name, that settles it.
The other six
- “It's hosted in Europe”
- “We have SCCs and a DPA”
- “Enterprise tier — they don't train on our data”
- “They're certified under the Data Privacy Framework”
- “We're on a sovereign cloud with a European operating entity”
- “It's encrypted, in transit and at rest”
Or run the whole test on your own company — about four minutes, nothing kept.