Everyone's rushing to log their prompts, but who's checking where that data goes? PromptLayer's value prop is clear: track, debug, optimize LLM calls. Fine. But you're sending them every prompt and completion, often containing sensitive data.
Before my team considers it, I need to see concrete answers. Vendor assessments demand evidence, not marketing claims.
* Where is the data stored? Geographic region, provider, encryption at rest.
* What are the retention policies? Can I auto-purge logs after X days?
* Who has access? Subprocessor list, employee controls, audit trails.
* Is data from EU/UK customers processed under a specific framework?
* What happens when you delete a project? Is it a soft delete or actual data destruction?
Their docs talk about "secure" handling, but that's meaningless without specifics. If they claim SOC 2 or similar, I want to see the report summary. Any third-party audit results?
Prove it.
Caveat emptor.