AI chatbot vendor due-diligence checklist

30 questions to ask any AI chatbot vendor - before signing

Buyer-side procurement checklist for AI chatbot vendors. We answer every question for SLAtech transparently and tell you how to verify each claim against any vendor. Pairs with answer-quality page, filterable vendor compare, and TCO calculator.

1. Compliance posture

If you serve regulated industries (Med, Legal, Edu, EU customers), compliance is a gating concern, not a nice-to-have.

  1. Are you HIPAA-compliant? Will you sign a BAA?
    Why it matters: Without BAA, your firm assumes liability for any PHI processed by the vendor.
    SLAtech answer: Yes - SLAtech Medical ships a BAA-eligible single-tenant option. BAA executed before any PHI ingest.
    How to verify: Ask the vendor to send you a sample BAA. If they say "contact sales" instead of sharing - that's a signal.
  2. Where is data stored? Can I require EU residency?
    Why it matters: GDPR + the 2025 Schrems-III decision tightened EU-to-US transfer requirements. Non-EU vendors carry transfer-risk.
    SLAtech answer: Hosting in your own jurisdiction is available on request (Enterprise deployments).
    How to verify: Look for explicit data-center geography on /trust/ or /security/. If the page only says "global cloud" without specifics - escalate.
  3. Do you have SOC 2 Type II or ISO 27001?
    Why it matters: Annual independent audit signals real security investment vs marketing claims.
    SLAtech answer: SOC 2 Type II audit in progress (closure Q3 2026). ISO 27001 timeline TBD based on EU enterprise traction.
    How to verify: Ask for the audit report (under NDA). "We're working on it" forever = red flag.
  4. Will you delete my data on contract end? Within how many days?
    Why it matters: Data-retention without explicit deletion clause leaves a forever-copy of your customer PII at the vendor.
    SLAtech answer: 30-day grace period after termination, then full deletion. Audit log of deletion provided.
    How to verify: Get this in writing in the MSA. "As required by applicable law" alone is not enough.

2. Eval / quality measurement

Any vendor can claim "powered by a leading LLM" or "94% accuracy". Real signal is a published, reproducible eval methodology.

  1. What eval methodology do you use? Is it published?
    Why it matters: Vendors who can't describe their eval process likely don't run one regularly.
    SLAtech answer: No published benchmark today. Answers built on retrieved content are scored for factuality and flagged when unsupported, visible to the customer for their own site.
    How to verify: Ask vendor to share a sample eval report. If they refuse "trade secret" - they're hiding something.
  2. What's your bot containment rate (% of conversations resolved without human handoff)?
    Why it matters: Containment rate drives ROI - a 50% containment vs 80% containment is a 30-percentage-point cost-of-support difference.
    SLAtech answer: Ask any vendor how they measure it and on whose content. Tracked per-tenant in the SLAtech dashboard.
    How to verify: Run a 100-conversation trial against your own traffic. Compare vendor's claim vs reality.
  3. How often do you re-run evals after model updates?
    Why it matters: Vendors who don't re-eval after model swaps risk silent quality drift.
    SLAtech answer: Every model swap triggers full eval rerun. Eval-score history published in changelog (/en/changelog/).
    How to verify: Check vendor's changelog / release notes for eval-rerun mentions. Absence = signal.

3. Multilingual + locale depth

If you operate in Israel, EU, or anywhere outside US-English, locale depth is a hidden differentiator.

  1. Do you support Hebrew RTL with proper bidi rendering?
    Why it matters: Hebrew RTL done badly produces garbled forms, broken date pickers, mis-aligned buttons. Most vendors only auto-translate, not localise.
    SLAtech answer: Hebrew RTL first-class, bidi-aware UI primitives, date/time/currency format locale-aware. Tested on every release.
    How to verify: Spin up vendor's demo in Hebrew. Send a message; check if response renders correctly, if date format is dd/mm/yyyy not mm/dd.
  2. Do you support Russian with native-locale phone/date/currency formatting?
    Why it matters: Russian-speaking diaspora is significant in Israel, Germany, Cyprus, Estonia. English-only chatbots leak this traffic.
    SLAtech answer: Russian first-class language, phone format +7 / +972 / EU formats auto-detected, ruble currency available.
    How to verify: Set vendor's demo language to Russian, test phone-number entry. Auto-formatting? Translation from English to Russian buttons?

4. Data portability + vendor lock-in

Lock-in is a common vendor strategy. Look for explicit data-portability commitments.

  1. Can I export all my conversation logs in standard format?
    Why it matters: Without export, switching vendors means losing all conversation history + training-signal investment.
    SLAtech answer: JSON Lines export of every conversation, 24-hour SLA on export request. No "per-export fee".
    How to verify: Ask vendor to demo export of 100 sample conversations. If they require a "data services SOW" - lock-in red flag.
  2. Can I export my knowledge-base / FAQ / training data?
    Why it matters: If knowledge-base is locked to vendor's schema, you're paying for the schema-conversion every switch.
    SLAtech answer: Markdown export of knowledge-base, source-of-truth stored in Git repo on customer side if customer prefers.
    How to verify: Ask vendor to demo knowledge-base export to standard format (Markdown, JSON, CSV).
  3. Will you charge me for switching off (egress fees, exit fees)?
    Why it matters: Some vendors hide vendor lock-in via prohibitive egress / exit fees.
    SLAtech answer: Zero egress fee. Zero exit fee. Documented in pricing page (/en/pricing/) and in MSA.
    How to verify: Get "no egress fee" in writing in the MSA. "Contact sales for pricing" = signal.

5. Pricing transparency

Per-conversation pricing with hidden overage is the dominant lock-in vector.

  1. Is your pricing published on the website?
    Why it matters: "Contact sales for pricing" alone signals enterprise-lock-in motion. Buyers should be able to budget without a sales call.
    SLAtech answer: Full pricing matrix at /en/pricing/ with live API-driven numbers. No "contact sales" gate for Starter/Pro tiers.
    How to verify: Check vendor's pricing page. If you can't get a number without email-gate - that's how procurement gets stuck.
  2. What's the cost per conversation in overage?
    Why it matters: Overage rate is where surprise bills hide. Some vendors charge 10× the base rate.
    SLAtech answer: Overage rate published per plan tier. Hard cap option available - bot stops vs unlimited overage.
    How to verify: Run TCO calculator (/en/tco-calculator/) with vendor's overage rate. Compare to base subscription.

6. Implementation timeline + ongoing support

Most enterprise chatbot deployments take 6-12 weeks with a forced implementation-consultant SOW.

  1. How long is a typical implementation? Is the consultant SOW required?
    Why it matters: Forced consultant SOW often costs more than the first year of subscription.
    SLAtech answer: Self-serve setup in 30-45 minutes for Starter/Pro. Custom Solutions tier offers white-glove (optional, not required).
    How to verify: Sign up for vendor's free trial. If setup wizard exists end-to-end, that's a signal of no-consultant motion.
  2. Who do I email for support? What's the response SLA?
    Why it matters: Tier-1 support routing to a ticket queue with 72-hour first-response is a common SaaS pattern. Mid-market expects faster.
    SLAtech answer: Direct email <a href="mailto:info@slatech.ai">info@slatech.ai</a> for founder reachability. 24-hour first response. Premium tiers get Slack Connect.
    How to verify: Email the vendor a pre-sales question. How long until response? Is it a human reply or canned template?

7. Roadmap + company stability

AI vendor space is volatile. Buying a chatbot from a pre-funded startup that goes under in 18 months is a risk.

  1. Is the company profitable? When was the last funding round?
    Why it matters: Pre-revenue startups burning through $20M / quarter risk shutdown / acquihire vs delivering roadmap.
    SLAtech answer: Bootstrapped (no VC) - sustainable from subscription revenue since 2025. Founder Emil Slavin (see /en/founder/).
    How to verify: Check Crunchbase / PitchBook for funding history. Bootstrapped or profitable = different risk profile than $200M Series C.
  2. What's your public roadmap?
    Why it matters: Vendors who don't publish a roadmap leave you guessing whether a feature is coming next quarter or next year.
    SLAtech answer: Public roadmap at /en/roadmap/ - current quarter shipping, next quarter committed, future quarter directional.
    How to verify: Look for public roadmap page. "Contact sales" or "we don't publish roadmap" = signal.

Want SLAtech's answers in a PDF?

Send us the email @ info@slatech.ai - we'll send a filled-in version for your procurement team. No marketing automation, no drip campaign - just the document.