An AI visibility platform RFP: what to require before shortlisting
A demo can show persuasive answers and still leave open who retains the data, what “ChatGPT coverage” means, or how you will leave the platform when the contract ends. Dashboard screenshots will not settle those questions. Ask every candidate for the same evidence before narrowing the field.
This RFP is for a team that knows what decisions it wants to make with AI visibility data and needs marketing, procurement, security and data owners to agree on requirements. It is not a vendor ranking. If you are still defining what a tracker should measure, start with the guide to metrics and limitations; for a market overview, see the GEO tools comparison.
Define the scope before sending questions
Describe the intended use on one page. Without that context, two affirmative answers may refer to different products.
- Brands and entities to measure; priority markets, languages and surfaces.
- Types of question: brand, category, product and competitor, with your intended unit of analysis.
- Expected users and teams; who administers, reads and exports.
- Data you will supply: prompts, client names, answers, labels or integrations. Flag what you cannot send.
- Decisions that depend on the data: executive reporting, alerts, investigations or audits.
- Retention period and the need to recover history on exit.
Do not require “all AI” when the decision depends on a defined set of surfaces. Do not request an accuracy guarantee without explaining what counts as a mention, recommendation, citation or valid response. Attach that data dictionary or ask each vendor to provide its definitions, examples and exceptions.
The response format matters as much as the question
Send a table with a stable ID for each requirement. For every row request a response (yes, partial, no or not applicable), scope (plan, region and surface), evidence (dated document or sample), dependency (configuration or third party), limitation, and proposed commitment. A checked “yes” with those fields empty should not earn a point.
Provide a shared clarification channel and circulate answers that change the scope to all participants. Separate public material from material subject to confidentiality. Do not ask one vendor to disclose another customer's data as evidence of quality.
The following matrix is a starting point. Replace the example priorities with your organization's own before sending it.
| ID | Requirement to ask about | Minimum evidence requested |
|---|---|---|
| D-01 | What is the exportable unit of observation and which fields does it preserve? | Schema and anonymized sample with prompt, surface, date, market, answer and labeling rules where available. |
| D-02 | How are missing answers, run failures and no brand mention distinguished? | State dictionary and one example of each state. |
| C-01 | Which surfaces, modes, countries and languages are actually observed? | Dated coverage matrix with method, exclusions and review frequency. |
| C-02 | Can an observation be reproduced and method changes identified? | IDs, available metadata and change log; disclose what is not retained. |
| S-01 | What data is stored, where, for how long and with whom is it shared? | Data-flow diagram, retention policy and applicable subprocessor list. |
| S-02 | How are users, permissions, support access and incidents handled? | Description of controls, responsibilities and notification process. |
| E-01 | How is the full history extracted and deletion requested at termination? | Export sample, process documentation and proposed timelines. |
| O-01 | What availability and support will be committed for this service? | SLA definitions, exclusions, maintenance windows and response times by severity. |
Do not assume every platform offers every sample field. The point of the RFP is to expose the difference between native data, a vendor's inference and a field that is not available.
Data and coverage: ask for definitions, not logos
“Gemini coverage” might mean API runs, a search-enabled interface, a particular mode or results collected by a third party. Ask which surface is queried, how, under what conditions, and which location, language, session and personalization differences can affect the result. Ask when the coverage matrix was updated; an undated sales screenshot cannot tell you what changed.
Ask the vendor to identify the original observation available, subsequent processing and the version of its rules. For any score, request the denominator, exclusions and reconstruction method. An inability to retain a full answer can be a legitimate method limitation; it should be declared rather than hidden behind a chart.
If vendors use the same name for different metrics, do not combine their numbers. The 14-day trial protocol lets you test definitions against your own dataset after shortlisting. This RFP only determines which commitments and tests deserve to reach that stage.
Security and exit: follow your data
Request the full path from the prompt you submit to the report you export: storage, location, support staff access, third parties, copies and deletion. Ask whether data may be used to improve models or services and under which configuration or agreement. Do not assume a favorable answer; require an explicit one.
A certification or standard questionnaire can reduce work, but it cannot replace a review of the actual contracted service and scope. The Cloud Security Alliance describes CAIQ as a tool for assessing cloud vendor controls. Use it to support security review, not as a seal of approval for this product or as legal advice.
For exit, ask who can initiate an export, in what format it arrives, which IDs connect the series and when access is removed. If no export sample is available, record the uncertainty. The detailed migration procedure is a later decision, but the right and practical ability to retrieve data should be clear before signing.
Support and SLA: distinguish commitments from expectations
Request an exact definition of availability: which component is measured, from where, with which exclusions and where status is published. A dashboard uptime promise is not necessarily a promise about prompt runs or export delivery. Define severity levels, support hours, first-response times, escalation route and handling of coverage changes.
Identify which terms will appear in the contract, which remain public documentation and which are non-binding expectations. Procurement and counsel should negotiate applicable obligations and remedies; this article does not prescribe a universal SLA.
Score documents before scoring demos
Set exclusion criteria first, such as an internal prohibition on sending particular data or a contractual need to export it. Do not bury them in a weighted average: a polished interface cannot offset a condition that prevents contracting.
For scorable items, use one documentary scale: 0 no answer; 1 claim without enough evidence; 2 partial evidence or a material limitation; 3 concrete evidence for the requested scope. Keep “not applicable” outside the denominator only if you decided that treatment before proposals arrived. Do not turn “to be confirmed” into a 2.
An illustrative allocation to structure the discussion is data and traceability 25, security and privacy 25, coverage and method 20, export and exit 15, support and SLA 15. The total is 100, but this is not a universal recommendation: adjust weights and gates with each function's owner before opening responses. Retain the ID, evidence, date, assessor and disagreements for every score.
The shortlist should also show unresolved questions and terms that need contractual drafting. A controlled trial may later disprove a documentary claim; it should not become an excuse to invent requirements after the fact.
The RFP should settle contractual exit terms; when switching vendors, this GEO tool migration procedure shows how to retain evidence and mark a series break.
FAQ
How is this RFP different from a 14-day trial?
The RFP records requirements, limits and documented commitments before selecting finalists. A trial uses your own data to check whether those claims hold in the intended use; a written answer cannot replace that verification.
Should I require coverage of every AI assistant?
Not by default. Define the assistants, surfaces, countries and languages relevant to your decision, and ask each vendor to document its method, limits and coverage changes. A row of logos does not prove that surfaces are comparable.
Is a security certification enough to approve a vendor?
No. Request the scope, validity and exceptions of the evidence, along with answers about your actual data flow, subprocessors, access, retention and exit. Your security team should review the applicable requirements.
How should I score an answer with no documentation?
Mark it as unproven, not as implicit partial compliance. Give the vendor the same clarification opportunity as the others and record which document or sample is missing before finalizing the score.
Can I use the template as a contract?
No. The RFP helps compare proposals and identify commitments that should later appear in the relevant contractual documents. Procurement, security and legal counsel should review the final terms.
Want to know if AI mentions your brand?
Discover your visibility in ChatGPT, Claude and Gemini in minutes.
Related articles
How to Evaluate an AI Visibility Tool in a 14-Day Trial
Run a 14-day AI visibility tool trial with a controlled dataset, acceptance criteria, QA, export checks and a documented final decision.
Practical GuidesAI Visibility Tracker: What a Serious Tool Should Measure (2026)
An AI visibility tracker should measure more than mentions: position, framing, competitors and changes by model. What to check before choosing one.
Practical GuidesGEO Tools in 2026: Complete Comparison to Choose the Best for Your Brand
We compare Mentio, Semrush, Ahrefs, Otterly, Profound and more. Find which GEO tool fits your budget and AI visibility needs.