Stage 0: Scope the purchase
Document modalities (text/image/audio/video), deployment constraint (cloud, Box, hybrid), expected volume, and whether beta modules are in scope. Separate **live** SKUs from **beta** pilots — beta must be initialed on Order Form, not assumed in MSA.
Stage 1: Trust Center diligence
Review /trust-center, security statement, subprocessors, and architecture pages. Note explicit gaps: SOC 2 Type I is under evaluation — not claimed. SSO/SCIM are not self-serve today. Use documented materials instead of demanding certifications that are not published.
Stage 2: Legal and DPA
Request MSA, DPA, and Order Form templates. Validate data categories processed, retention defaults, subprocessor list, and breach notification clauses. AI verification vendors process content — ensure purpose limitation matches your use case.
Stage 3: Technical validation
Run API smoke tests, review OpenAPI/Postman assets, and validate signed PDF + QR outputs in your case system. Confirm rate limits, credit model, and 402/429 handling. For EU buyers, test Article 50 artifact exports if in scope.
Stage 4: Commercial structure
Map plans: Starter (self-serve API), Compliance Pack (€449/mo wedge), Enterprise (MSA/SLA). Avoid paying Enterprise scope for Starter needs — but escalate when procurement requires contractual SLA or Box deployment.
References when logos are not public
Ask for: (a) scoped POC with success criteria, (b) Trust Center walkthrough, (c) design-partner pilot path at /enterprise/design-partner-program, (d) comparison matrices with public-source cells. Do not accept invented customer counts.