Congrats on the demo. On the security question - what they're really asking is where does our data end up, so answer it contractually before you answer it technically. The major providers don't train on business API traffic by default, and enterprise agreements can add zero retention, so get that in writing and put it in your proposal. Then the technical side: give the agent its own credentials rather than a human's, scope them to the minimum it needs, and log every tool call it makes so there's an audit trail you can hand over. The credential scoping is the part people skip and it's the one that actually limits blast radius if something goes wrong. Worth writing all of this into a one-page security note you attach to every pitch, because this objection will come up in every deal from here.