1. Read-only, or read-write? A tool that can only read cannot corrupt a CRM record or send an email as one of your people. If a vendor needs write access, make them name exactly which object and why.
2. Metadata or message content? Scoring a relationship needs frequency, recency and direction - who emailed whom, how often, how recently. It does not need the body of the email. A vendor reading content has a materially larger problem to defend in your security review.
3. Whose tenant holds the graph? Some vendors keep each customer's graph isolated. Others pool relationships across their customer base, so your coverage includes relationships your company does not have. That is a genuine feature and a genuine governance question, and it should be a deliberate choice rather than a surprise.
4. How is access revoked? Not just "can we cancel" - at what granularity, and how fast. Per client, per user, per organisation.
Worth checking any vendor's docs rather than their sales deck. Orbb's are public:
SOC 2 and GDPR-readiness are covered on Orbb's trust page; for a security questionnaire, ask the customer team rather than relying on a marketing claim.
Separately from the vendor's posture, mapping your team's communications has obligations on your side under GDPR: a lawful basis, usually legitimate interests; a completed balancing test; an entry in your processing register; and a route to honour deletion requests.
The practical safeguard that does most of the work is telling your employees before you switch it on. It is also the one most often skipped.
"We're fully secure and compliant." Every vendor says it.
The answer worth hearing names a mechanism: which scopes, which direction, which tenant, which audit log, and how to turn it off in a hurry.