---
title: "Synthetic Research Security and Procurement Compared | Minds"
canonical_url: "https://getminds.ai/comparison/synthetic-research-security-and-procurement"
last_updated: "2026-08-26T19:31:35.143Z"
meta:
  description: "Compare synthetic research vendors by DPA, subprocessors, TOM, DPIA, SLA, data residency, training policy, deletion, SSO, auditability, and model changes."
  "og:description": "Compare synthetic research vendors by DPA, subprocessors, TOM, DPIA, SLA, data residency, training policy, deletion, SSO, auditability, and model changes."
  "og:title": "Synthetic Research Security and Procurement Compared | Minds"
  "twitter:description": "Compare synthetic research vendors by DPA, subprocessors, TOM, DPIA, SLA, data residency, training policy, deletion, SSO, auditability, and model changes."
  "twitter:title": "Synthetic Research Security and Procurement Compared | Minds"
---

Minds

August 21, 2026·Comparison·Minds Team

# **Synthetic Research Security and Procurement Compared**

Procurement readiness is evidence, not a trust badge. Buyers should compare the actual DPA, subprocessor, security, deletion, service, model-provider, and validation commitments that apply to their deployment.

[Evaluate Minds](https://getminds.ai/?register=true)

Synthetic research systems can process customer briefs, interview transcripts, respondent data, product plans, creative assets, and strategic questions. A polished demo does not answer how that material is stored, routed, retained, reused, or deleted. Procurement readiness must be assessed from the documents and controls that apply to the actual deployment.

Minds and Artificial Societies both publish meaningful legal material. Aaru publishes an MSA and DPA. Electric Twin exposes privacy, terms, and a trust-center path. Simile publishes privacy and participant terms and signals substantial enterprise-security investment. Public visibility differs, but absence from a public page is not proof a control does not exist. Mark it as not publicly available and ask for evidence.

## Procurement evidence matrix

| Evidence | What it should answer | Minds public path |
| --- | --- | --- |
| DPA | Roles, instructions, processing, transfers, deletion, audit, breach terms | [Data Processing Agreement](https://getminds.ai/legal/dataprivacy) |
| Subprocessors | Vendor, purpose, processing region, change notice | [Subprocessors](https://getminds.ai/legal/subprocessors) |
| TOM | Access, encryption, separation, resilience, incident controls | [Technical and Organizational Measures](https://getminds.ai/legal/tom) |
| DPIA | Processing risks, necessity, proportionality, residual controls | [Data Protection Impact Assessment](https://getminds.ai/legal/dsfa) |
| SLA | Availability, support, exclusions, recovery and credits | [Service Level Agreement](https://getminds.ai/legal/sla) |
| Pricing and plans | Baseline access, limits, and upgrade path | [Pricing](https://getminds.ai/pricing) |
| Model-change provenance | How material system changes affect validation and disclosure | [Model-change policy](https://getminds.ai/research/model-change-validation-provenance) |

Publication does not mean every term applies to every plan. The signed order form, DPA, SLA, and customer-specific agreement control the commercial and legal relationship.

## Customer-data training

Ask whether customer prompts, files, answers, embeddings, logs, and feedback are used to train a vendor model, a third-party general-purpose model, or neither. “We do not train on your data” must specify the actor, purpose, opt-in state, and exceptions.

Minds' public legal material states the applicable processing purpose and no general-purpose model training unless expressly opted in where available. Buyers should verify provider-specific retention and zero-data-retention configurations for their deployment. Apply the same precision to every vendor.

## Subprocessors and model providers

Synthetic research often spans hosting, databases, object storage, analytics, search, transcription, embeddings, and multiple model providers. A complete subprocessor list should name the purpose and processing region. It should also distinguish a service the customer connects independently from a processor the vendor engages.

Artificial Societies' DPA is unusually informative about parts of its architecture and deserves credit for that transparency. Simile's participant terms are also relevant because participant-data rights are part of its human-data moat. The correct response is not to penalize visible detail; it is to require equivalent detail from every shortlisted vendor.

## Data residency and transfers

“EU hosted” is not the same as “all processing stays in the EU.” Infrastructure, model inference, support, telemetry, and optional integrations may cross regions. Request a data-flow diagram for the exact configuration, including backup and log locations, transfer mechanisms, and customer-controlled integrations.

Minds describes EU-primary infrastructure and third-country processing for selected services in its legal pack. The [DPIA](https://getminds.ai/legal/dsfa) and [subprocessor page](https://getminds.ai/legal/subprocessors) should be read together rather than reduced to one hosting sentence.

## Access, identity, and tenant separation

For enterprise deployments, verify authentication, role and workspace boundaries, tenant isolation, API credentials, audit trails, and deletion authority. SSO or SCIM should be recorded as generally available, plan-dependent, add-on, custom, or not publicly available. Do not turn a roadmap item into a current feature claim.

The Minds feature catalog treats customer-managed SAML SSO as a configured enterprise capability where agreed. Shared-workspace editing follows role and sharing scope. API and MCP access are subject to authentication, limits, and plan configuration. These details matter more than a generic enterprise-ready label.

## Retention, deletion, and exports

Buyers need separate answers for active data, deleted data, backups, logs, derived embeddings, exported artifacts, and third-party systems. Confirm deletion timelines after termination and the process for early deletion or legal holds. Confirm that the customer can export the evidence required for audit or migration before deletion.

Minds supports structured exports for eligible Study, audience, answer, transcript, summary, persona, and result data in supported formats. Availability depends on the plan and workflow. An export feature is not a substitute for a contractual deletion term; both are required.

## Availability and incident response

An SLA should define uptime, exclusions, support priorities, notification, recovery objectives, and credits. Synthetic research also depends on third-party AI and data services, so the vendor should explain graceful degradation and what happens to an in-progress study during an outage.

Do not copy a marketing response-time claim into a contract comparison. Use the applicable SLA and order form. Ask for status history and incident evidence where the decision is material.

## Model and provider changes

A model change can alter output quality and data processing at the same time. Procurement should require an evaluation of material provider changes, subprocessor notice where applicable, and a scoped benchmark regression before a public validation claim is carried forward.

Minds commits to record material research-system changes that affect public benchmark interpretation and to disclose the tested system envelope. Read the [full provenance policy](https://getminds.ai/research/model-change-validation-provenance).

## Buyer checklist

1. Collect the current DPA, subprocessor list, TOM, DPIA or risk assessment, SLA, and privacy notice.
2. Map every data type to vendor, purpose, region, retention, and deletion.
3. Record customer-data and participant-data training rights.
4. Verify tenant isolation, roles, SSO, API credentials, and audit controls.
5. Separate generally available controls from add-ons and custom terms.
6. Test exports and deletion before signing.
7. Define notice and regression requirements for material model changes.
8. Match validation and human review to the risk of the decision.

## Related resources

Use the [procurement checklist](https://getminds.ai/guide/synthetic-research-procurement-checklist), [self-serve vs managed comparison](https://getminds.ai/comparison/self-serve-vs-managed-synthetic-research), [data-source comparison](https://getminds.ai/comparison/synthetic-audience-data-sources-compared), [research evidence center](https://getminds.ai/research/synthetic-research-evidence-center), and [Artificial Societies alternatives](https://getminds.ai/blog/artificial-societies-alternatives).

## **Frequently asked questions**

### **What documents should a synthetic research vendor provide?**

At minimum, request the DPA, subprocessor list, technical and organizational measures, privacy notice, deletion and retention terms, security overview, service commitments, incident process, and a description of model-provider and customer-data use.

### **Does Minds publish a procurement pack?**

Minds publishes an English DPA, subprocessor list, TOM, SLA, and DPIA in its legal center. The applicable order form and customer-specific configuration still control plan limits, enterprise additions, and negotiated terms.

### **Why do model changes belong in procurement review?**

A provider or model upgrade can change outputs, data flows, subprocessors, regions, retention behavior, and benchmark comparability. Buyers need notice and regression rules for material changes, not only a static model name.