09
Security, privacy, and vendor risk
Before sending data to a model or retrieval service, understand what is transmitted, where it is processed, how it is retained, who can access it, and whether the provider may use it for service improvement.
Minimize sensitive data, separate tenants, redact where appropriate, and avoid placing secrets in prompts or tool context. Access control, audit logs, deletion, backups, incident response, and data export remain application responsibilities.
A Bangladesh-based delivery team may still use model, vector, observability, or cloud providers outside Bangladesh. The buyer should approve what data may leave its environment, provider retention settings, account ownership, billing currency, service regions, deletion behavior, and the fallback path before production data is connected.
High-stakes legal, medical, financial, employment, safety, or regulated use requires specialist review beyond ordinary product engineering. The project scope should identify the responsible experts and independent assurance rather than implying that model integration creates compliance.