Hey everyone, been lurking here for a bit but this latest news has me pretty anxious. I saw the headlines about the AI vendor breach where sensitive customer data was exposed due to a misconfigured API. We just started a pilot with Claw AI for our internal document analysis, and honestly, I'm second-guessing everything now.
Our use case involves some non-public operational data. We're not in healthcare or finance, but we do have contractual confidentiality obligations with our clients. My understanding is that Claw's deployment model is "bring your own key" for encryption, which we opted for. But after this breach elsewhere, I'm realizing I don't fully know what that *actually* means in practice.
I'd love to get the community's take on what we should be asking Claw, specifically. My main concerns:
* Where is our data processed and stored at rest? Is it truly isolated per tenant?
* What's the scope of their SOC 2 report? Would their Type II cover the specific components we're using?
* For the "bring your own key," how is that key managed? Who has access to the encryption/decryption environment on their end?
I feel like I'm going down a rabbit hole trying to map this to a framework like ISO 27001 controls. Has anyone done a recent vendor assessment on Claw or a similar AI-as-a-service provider? I'm especially curious about how you validated their incident response process and data deletion procedures.
We're on a tight budget, so switching to a fully on-prem AI tool isn't really an option. But this feels like a moment to really scrutinize before we go from pilot to full production. Any guidance on specific questions to ask or red flags to look for would be so appreciated.