Know, Like, Trust and Revenue
The demo went well. It usually does by now.
Five years ago, the hard problem was actually building something, and most teams never got there. Today a small team with good tooling can ship enterprise-grade functionality in a matter of weeks, and the demo lands. The buyer is enthusiastic. Someone forwards it internally with a note that says we should look at this.
Then week two arrives, and nobody is talking about the product anymore.
What arrives instead is a spreadsheet. Sometimes it is three hundred rows, sometimes it is a polite email with four questions in it, and the tone is never adversarial. The person sending it is not trying to kill the deal. They are trying to get to a position where they can sign off, and they need a set of things to be true before they can. The founder reads the questions, recognizes most of the words, and starts assembling answers.
That assembly is where the deal dies. Not because the answers are wrong, but because they are being written in response to the question.
The four questions underneath every questionnaire
However long the document is, it resolves to four things. The rest is elaboration.
Who else can reach this data. Most AI products are built in a shared development subscription, because at the beginning that is the right call - it is fast, it is cheap, and nobody is asking. The answer that comes out under review is every engineer, two contractors, and whoever still has a key from last year. That is not a technical failure. It is a governance failure, and it does not get fixed with a paragraph.
What happens when the model is wrong. Not whether it hallucinates - the reviewer already assumes it does. They want to know what sits between a wrong output and a consequence. Who reviews it, what gets logged, and how anyone would know afterward. A confidence score is not an answer to this question.
Who is in your supply chain. Every model provider, every inference host, every vector store is a subprocessor, and each one is a party the enterprise is being asked to trust without having selected. Swapping an inference provider for a better price is a routine engineering decision right up until it becomes a contractual disclosure you did not make.
What happens when you are gone. The buyer is evaluating a company that has existed for eighteen months. They are not being rude. They are asking what they own, what they can export, and what happens to their operation if you are acquired or you stop answering email.
None of these are questions about the product. All four are answerable. The problem is when.
Evidence has a timestamp
A security reviewer is not reading your policy for its contents. They have read a hundred of them and they are all substantially the same document. They are reading it for whether it looks like something you operate or something you produced.
A data retention policy dated eleven days ago, arriving in the middle of a review, tells them exactly one thing. It does not matter that the policy is good, or that your practice was already sound and you simply had not written it down. The date is the signal. It says this was assembled in response to being asked, which means the reviewer now has to independently verify anything else you hand them, which means the timeline you gave your board is gone.
This is the part that is genuinely hard to internalize when you are building fast. Nearly everything else in an early company can be produced on demand. Pricing, positioning, the deck, even the feature - all of it can be built in the moment and it works fine. Evidence is the one category that cannot, because its value comes from having existed before anyone asked for it.
The founders who clear enterprise review are almost never the ones with better security. They are the ones who made a small number of decisions early - tenancy, logging, subprocessor documentation - that produce evidence as a byproduct of operating. When the questionnaire arrives they are not writing. They are exporting.
Why this is getting worse, not better
Two things are moving in opposite directions.
Enterprise buyers are getting faster at the front of the process. AI has broken the assumption that a capability takes eighteen months to build, so pilots are being approved on shorter timelines and with less internal debate than they were two years ago. Getting the meeting is easier than it has ever been.
The back of the process is tightening. The same enterprises now have AI-specific review criteria that did not exist in their vendor packets in 2024, driven by regulators, by their own boards, and by watching a peer get embarrassed. The review is longer, more specific, and staffed by people who have now seen enough AI vendors to know which answers are rehearsed.
The window between those two things is where a company either becomes purchasable or does not. It is not a sales problem and it is not an engineering problem, but it is your biggest and most important problem to solve.