primedefence
Private inferencePlaybook

Private AI vendor assessment: an enterprise checklist

Align business, IT and security around exclusion requirements, supplier evidence, pilot acceptance, operating commitments and exit.

By Daute Delgado Updated 2026-09-09 6 min read

Prepare a common procurement brief

Private AI proposals need to describe comparable services. One may include only model access; another may cover infrastructure, support and a document interface. Without separating those layers, price comparison is misleading. Prepare a brief covering task, users, volume, data, integrations and service hours. Ask each supplier to mark every component included, optional or excluded.

Assign a business owner who can judge usefulness and a technical owner who can review operation. Security validates data flows and controls; procurement consolidates conditions and exclusions. This division prevents a sales demonstration from being accepted as technical evidence or an essential requirement from appearing only after award. Maintain questions and responses in one versioned record.

Define what is not being purchased. Retrieval, fine-tuning, business chat, identity integration and connectors can be separate scopes. Suppliers should identify which components are included in the pilot and which require later work. The private AI business guide establishes the terminology needed for a precise request.

Requirement and evidence matrix

Use one row per requirement and add reviewer, evidence received, date and decision. A console screenshot may demonstrate a setting at one moment without proving that the control works. Where practical, combine documentation with an agreed test. Record limitations instead of interpreting silence as a positive answer.

Procurement questionRequested evidenceInsufficient response
Where is each data type processed?Flow map, locations and componentsOnly the model server is identified
Who can access it?User, service and support rolesEncryption is the only answer
What is retained?Logs, cache and backup policy and settingsNo training is confused with no logging
What load can it support?Context, concurrency and percentile measurementsA token maximum without conditions
How are updates handled?Versions, regression tests and rollbackAutomatic updates without acceptance
What happens during failure?Recovery procedure and rehearsalUnspecified redundancy
How does the agreement end?Export, revocation and deletion processNo owner for removing access

Separate exclusion requirements from preferences

An exclusion requirement determines whether a proposal can remain in the process. It might concern data handling, an essential integration or minimum task acceptance. Define it in testable terms and approve it before reviewing bids. If it changes during evaluation, record the reason and apply the revised requirement consistently to every candidate.

Scored criteria compare proposals that already satisfy essential conditions. They may include operational clarity, integration effort, observed quality, recovery and total cost. Do not allow an average score to compensate for unauthorised data access with a price reduction. The private LLM security checklist can support technical review, but it is not a certification of compliance.

Use a scoring method you can explain

A practical evidence scale can distinguish an unsupported claim, partial documentation, a successful test with limitations and a successful test under the agreed conditions. Weights should reflect the use case rather than a universal template. If continuity is essential, it should matter more than an interface feature used occasionally. Keep the rationale beside the score.

Missing information should remain pending, not receive a neutral score. Request clarification and set a response date. When a supplier proposes an exception, identify its impact and the person authorised to accept it. The final record should distinguish what is known, what has been tested and what remains conditional. A reviewer who missed the meetings should still understand the recommendation.

When Primedefence bids for implementation, its proposal should be evaluated under the same criteria as other candidates. That engagement is not described as an independent assessment of our own solution. A clear distinction allows the buyer to arrange external review when the procurement process requires it.

Require a comparable pilot with an explicit exit

Provide an agreed sample, using synthetic or anonymised inputs until data conditions are settled. Hold back some cases for final evaluation rather than allowing every example to tune the demonstration. Keep quality criteria and workload consistent. If a supplier tests a different configuration from the one quoted, label the result and repeat affected tests before acceptance.

The pilot needs a proceed, correct or stop decision, plus a plan for data and resources when it ends. Establish who pays for additional testing, which artefacts the customer receives and whether any later commitment exists. The pilot evaluation guide describes the evidence pack and acceptance process in more detail.

Security testing requires authorisation and scope. Permission, rate-limit and logging checks do not need destructive activity. Define test accounts, data and stop conditions. The OWASP Top 10 for LLM applications helps identify risk categories to translate into checks for the actual system, rather than treating a generic checklist as proof.

Translate tested behaviour into operating commitments

The agreement and technical schedules should describe the delivered configuration, changes requiring approval, incident notification and ownership by layer. An availability commitment needs a measurement window, exclusions and a claim process. Distinguish support response time from restoration time; acknowledging an incident is not the same as returning the service to operation.

Separate implementation, capacity, operation, expansion and optional services in the price. Review minimum commitments and additional usage or assistance charges. The cost guide supports a comparison per accepted task. For operational handover, use the private LLM operations guide and verify that the named owners can execute the procedures.

Before award, rehearse exit on a sample: export configuration, revoke an account, retrieve artefacts and check backup treatment. Do not wait until termination to discover which elements are portable. Preserve the recommendation, accepted exceptions and conditions still requiring verification in the procurement record.

What to request in an initial proposal

Request a short, testable scope with assumptions, deliverables, exclusions, a schedule linked to dependencies and an itemised budget. Attach the workload and data requirements. A supplier should explain what information is missing without filling the gaps with generic guarantees. That clarity is useful evidence of how the engagement will be managed.

Primedefence private inference services begin with that feasibility definition. Use this matrix to assess our proposal or another candidate's. The procurement decision and acceptance of residual risk remain with the buyer.

Frequently asked questions

Does supplier certification replace testing?

No. It may provide organisational context, but scope, currency and service-specific controls still need review. Task quality and capacity require use-case testing.

Should we select the largest model?

Not by default. Evaluate task quality, licence, latency, resource use and cost. A larger model may increase expenditure and response time without improving usable output.

Is a sales demonstration sufficient?

Not for production acceptance. Convert it into a test with recorded inputs, configuration, workload and criteria, then review access, operation and recovery.

Daute Delgado

Written by

Daute Delgado

CEO & Co-founder, Primedefence

Daute Delgado is CEO and co-founder of Primedefence. He spent more than a decade defending airlines, managed SOCs and international organizations, first as an operator and later leading security teams.

View full profile

Is private inference right for your business?

Define your use case, data requirements and pilot acceptance criteria.

Explore private inference services

Related articles