Home / Knowledge / AI & LLM
AI & LLM

How to Evaluate AI Vendors

A checklist for choosing an AI vendor — security, SLA, Thai-language support, compliance, cost lock-in, and having a real exit plan

Picking an AI vendor is like choosing a caterer for a wedding — tasting good food isn’t enough. You need to know if they show up on time, what happens if the kitchen catches fire on the day, and whether you can switch caterers next year without losing your deposit.

This is a short checklist to run through before signing with any AI vendor — whether it’s a raw API (OpenAI, Anthropic, Google), a SaaS platform with AI baked in, or a local vendor building a custom solution.

1. Security — where does your data actually go

The first question to ask: what happens to the data you send in?

  • Is it used to train future models? If the default is “yes,” find the opt-out, or move to an enterprise plan where it’s off by default.
  • How long are logs kept? Some vendors keep conversation logs for 30 days, others indefinitely. Know how long your customer data floats around in someone else’s system.
  • Is data encrypted in transit and at rest? This is a baseline requirement, not a nice-to-have.
  • Is there an audit log? If something goes wrong, you need to trace who called the AI, when, and with what data.

Simple test: if you wouldn’t hand your house key to a neighbor you barely know, don’t hand your customer data to a vendor who can’t answer security questions clearly.

2. SLA — how much downtime are they promising

An SLA (Service Level Agreement) states what percentage of time the service should be up — e.g., 99.9% uptime means roughly 8.7 hours of allowed downtime per year.

What to check:

  • Is the uptime number concrete? If a vendor just says “we’re highly reliable” with no number, be wary.
  • Is there compensation for breaching the SLA? Usually service credits, not cash refunds.
  • What’s the response time during an incident? If the system goes down at 3am, does anyone pick up, or do you wait until Monday morning?
  • Is there a fallback if the primary AI provider goes down? E.g., if OpenAI has an outage, can you fail over to another provider?

Common mistake: reading only the uptime percentage without reading what counts as “down.” Some vendors only count full outages, not the API being so slow it’s effectively unusable.

3. Thai support — who do you talk to when something breaks

This matters more than people expect, especially if your team isn’t fluent in English or your use case depends on Thai-language context.

  • Is there a support team that speaks Thai? If every ticket needs translation back and forth, that delay is a real cost.
  • How good is the model at Thai, really? Test it on actual use cases — summarizing Thai legal documents, replying to customers in polite Thai register — not just simple questions.
  • Is there a local partner or reseller in Thailand? They often help with contracts, tax, and faster support than dealing with an overseas HQ directly.
  • Can contracts and documentation be provided in Thai? Legal will thank you.

4. Compliance — does it hold up under Thai and international standards

  • PDPA (Thailand’s Personal Data Protection Act) — the vendor needs a Data Processing Agreement (DPA) that clearly states who’s the data controller and who’s the data processor.
  • Where is data hosted? Some industries (finance, healthcare) require data to stay in specific regions. Check whether the vendor has data centers that meet your requirements.
  • International standards — ISO 27001 and SOC 2 Type II are baseline proof that a third party has audited the vendor’s security practices.
  • Industry-specific rules — finance or healthcare businesses may need extra standards, like PCI-DSS for card data.

5. Cost lock-in — cheap today, expensive later

Many vendors use a low introductory price to get you in, then raise prices once switching becomes painful — like a phone plan that’s cheap in year one and doubles in year two.

Things to check:

  • What does long-term pricing actually look like? Ask directly how pricing changes in year two and beyond.
  • Are you tied to a custom or fine-tuned model on one platform? If you invest in fine-tuning on a specific platform, leaving might mean starting from scratch.
  • Hidden costs — storage fees, data egress fees, higher-tier support costs.
  • What are the terms of volume discounts? Cheaper rates often require committing to usage volumes a year in advance.

6. Exit plan — can you actually leave if you want to

This is the thing people forget to check when signing, because nobody thinks about leaving on day one. But businesses should plan for it like insurance — you hope you never need it, but you need it to exist.

  • Can you export your data easily? Conversation logs, configurations, fine-tuned models (if any).
  • Is the exported format usable elsewhere? Or does it come out in a proprietary format that’s useless anywhere else?
  • What’s the required notice period to cancel? Some contracts require 90 days’ notice, or they auto-renew for another year.
  • Are there early termination penalties? Especially in enterprise contracts with committed usage volumes.

Checklist before signing

□ Security: data isn't used to train models without explicit consent
□ Security: encryption + audit logs in place
□ SLA: concrete uptime number + compensation for breaches
□ Thai support: Thai-speaking team + model genuinely handles Thai well
□ Compliance: DPA covers PDPA + international standards (ISO 27001 / SOC 2)
□ Cost: you know the pricing structure for the next 2-3 years, not just year one
□ Exit plan: data is exportable + cancellation terms are clear

If a vendor can’t answer these questions, or dodges them, that’s a bigger warning sign than a competitor’s lower price. The most expensive part of choosing the wrong vendor is rarely the monthly bill — it’s the day you try to leave and can’t.