| Can you reprocess your own historical data when your extraction improves? | A platform that only parses at ingest is frozen at the quality of the day it collected. When its extraction gets better, everything already held stays exactly as bad as it was — and that corpus is usually the largest thing you are paying for. | “Our extraction is already accurate.” Or a description of how new data will be parsed, which answers a different question. |
| Follow up with: when did you last reprocess, what changed, and did anything land in a customer tenant as a result? |
| Do you publish the vocabulary your system uses to classify a finding? | A closed, readable verdict set is a commitment: it names the states a finding can be in and what each one licenses you to do next. An unpublished one lets “high” mean whatever this quarter of model output happens to mean. | “Findings are scored one to a hundred.” A score is a ranking, not a vocabulary — ask what a 71 means that a 68 does not. |
| What happens to a finding your AI judged benign? | Every platform in this category now has a model deciding what not to show you. The question is whether that decision is visible, reversible and reviewable, or whether the discarded pile is simply gone. | Any statistic about how rarely it gets that wrong. That is a claim about the pile you cannot see, produced by the party that made it disappear. |
| Ask to see the suppressed queue during the trial, reverse one decision, and confirm the finding comes back with its evidence intact. |
| Does detection terminate in removal, or in an alert? | Finding an impersonating domain and getting it removed are different businesses with different cost structures. Many platforms detect and hand you an abuse contact; some file on your behalf; fewer do it inside the subscription rather than per incident. | “We support takedowns.” Ask who files, under whose authority, what evidence pack goes with it, and whether it is metered. |
| Is active validation bounded to inventory you attributed to me? | Testing an asset that turns out not to be yours becomes your incident, not the vendor’s. The bound matters more than the technique: validation should run only against assets already tied to you with evidence, inside a scope somebody signed. | “We test everything we discover.” Careful attribution and unbounded testing are in tension, and a vendor claiming both has usually not thought hard about the second. |
| Can I reconcile your activity against my own logs? | You should be able to take a window of vendor testing and find it in your WAF, CDN and edge logs — source addresses, user agents, timing. If you cannot, you have no way to separate vendor traffic from a real attacker during the trial, and no way to audit the boundary you agreed. | “We test from a rotating cloud pool.” Rotation is reasonable; declining to disclose the ranges and windows is not. |
| What does the second year cost, and which units are metered? | Renewal is where a discounted first year gets recovered, usually by metering something the trial made look unlimited: assets, takedowns, seats, historical retention. Every one of those is cheap to agree in year one and expensive to argue about in year two. | “We will look after you at renewal.” Ask instead for the uplift cap and the metered units, in the contract, before the first year starts. |
| What do I take with me if I leave? | The findings, the evidence, the attribution decisions and the disposition history are your operational record, and in a regulated environment they are audit evidence. Most platforms export current state; fewer export the history that makes current state defensible. | “Everything is on the API.” Ask specifically for evidence artefacts and state-change history, not the current finding list. |
| Who is on the other end when a finding is wrong? | By month nine the thing deciding whether a platform is renewed is rarely detection quality. It is whether a disputed finding reaches somebody who can change the system, rather than somebody whose job is to log that you were unhappy. | “You get a dedicated CSM.” Ask what that person is able to change — a detection rule, an attribution decision, a suppression — and how long it took last time. |