Buyer question matrix
B2B prompts combine team, stack, security, region, and commercial constraints. These questions follow the buyer from category discovery through implementation.
Awareness: define the category and evaluation criteria
The buyer needs category boundaries and useful selection criteria before naming vendors.
- Which type of SaaS should a mid-market revenue team use to reconcile product usage with CRM data?
- What should I look for in a B2B SaaS platform that will handle customer data across the EU and the US?
- How do AI assistants decide which enterprise software vendors to include in an initial shortlist?
- Why does our SaaS appear for branded searches but disappear when buyers ask category questions?
- How can I check whether ChatGPT, Perplexity, and Gemini understand what our product actually does?
Comparison: align product and commercial constraints
Candidates are compared on deployment, integrations, governance, and pricing mechanics.
- How do X and Y differ on usage-based pricing, API rate limits, and support response terms?
- Which alternative to X supports EU data residency, SAML SSO, SCIM provisioning, and customer-managed keys?
- Is seat-based or usage-based pricing easier to forecast for a team with seasonal demand?
- How should I compare SOC 2 Type 2 and ISO/IEC 27001 evidence across SaaS vendors?
- Which X alternative has a public API, a usable sandbox, and an export path that does not require custom services?
Decision: verify evidence and contract scope
Each review function needs scoped documents, not broad claims.
- Is X actually covered by a current SOC 2 Type 2 report, and which system and trust services categories are in scope?
- Does X act as a processor or controller for account data, customer content, and product analytics?
- Where does X host EU customer data, and can its sub-processors access that data from another region?
- What happens to our data, integrations, and audit logs when the subscription ends?
- Does the SLA cover the components we use, and how are exclusions, notices, and service credits defined?
Use: integrate, govern, troubleshoot, and renew
Answers should resolve to a current API version, admin guide, status record, or contract.
- Why did our integration start returning this error after the API version changed?
- How do I map SAML groups to roles and deprovision users through SCIM in X?
- Where can I see whether this incident affects the API, dashboard, or data pipeline?
- How can finance separate added seats, usage overages, and contracted minimums on this invoice?
- Which export formats and deletion steps should we test before renewing X?
Terms and product signals
English-language evaluation uses different entities from Chinese procurement. Reports, certifications, contracts, controls, and pricing units answer separate questions.
Security, privacy, and procurement evidence
| Term | Role in an AI answer |
|---|---|
| SOC 2 Type 2 report (often written Type II) | Independent CPA examination evidence for a named system, trust services categories, and period; not a certification. |
| ISO/IEC 27001 certification | Identifies the certified management-system entity, scope, edition, certification body, and certificate status. |
| Data Processing Addendum (DPA) | Defines instructions, security duties, assistance, deletion, audits, transfers, and sub-processor conditions. |
| Controller | Names who determines the purposes and means of processing; roles may vary by data use. |
| Processor | Describes work for a controller under documented instructions and contract terms. |
| Sub-processor | Identifies each downstream processor, processing function, location, authorization, change notice, and flowed-down safeguards. |
| EU data residency | States storage location; remote access, support, telemetry, backups, and transfers remain separate. |
| Standard Contractual Clauses (SCCs) | Identifies a transfer mechanism; selected modules, parties, annexes, and safeguards matter. |
| Trust center | Indexes scoped security documents, policies, certificates, sub-processors, and request procedures. |
| Security questionnaire | Reconciles buyer-specific security responses with reports, policies, architecture, and contracts. |
| Penetration test summary | States tested scope, date, assessor, and remediation status without making a broad guarantee. |
| Data retention and deletion | Explains retained data, duration, backups, termination handling, and verified deletion requests. |
Administration, reliability, integration, and pricing
| Term | Role in an AI answer |
|---|---|
| SAML single sign-on (SSO) | Signals identity-provider compatibility and supports authentication and access-policy questions. |
| SCIM provisioning | Explains automated onboarding, group changes, role changes, and deprovisioning. |
| Role-based access control (RBAC) | Maps roles to permissions and data scope for administrative separation and least privilege. |
| Audit logs | Records user and administrator events; retention, export, search, and fields determine value. |
| Service Level Agreement (SLA) | Defines measured service, availability method, exclusions, notices, support, and contractual remedy. |
| Status page | Provides incidents, affected components, update history, and recovery notices. |
| Recovery Time Objective (RTO) | States target restoration time; contract scope and test evidence remain relevant. |
| Recovery Point Objective (RPO) | States target data-loss window, distinct from service restoration time. |
| API versioning and rate limits | Defines compatibility, deprecation, throughput, retry, and error behavior. |
| Seat-based pricing | Ties charges to user or role counts; each billable seat state needs definition. |
| Usage-based pricing | Ties charges to a meter; allowance, overage, and reset rules shape cost. |
| Sandbox environment | Provides a separated place to test APIs, permissions, workflows, and sample data. |
AI citation-source map
This map names concrete citation candidates, not a universal ranking. Freeze prompt, engine, date, locale, and account conditions; archive displayed sources and their pages.
Chinese-language engines (Doubao / Qwen / DeepSeek / Wenxiaoyan)
| Source type | Specific source | Why it may be cited |
|---|---|---|
| Chinese product documentation | A vendor's public Chinese help center, API reference, service notices, pricing page, and filing links | Provides localized feature, integration, service, and entity facts when access, URLs, and dates are clear. |
| Business and product analysis | TMTPost and Leiphone | Adds market context, company changes, and launches; syndicated announcements need another check. |
| Developer communities | OSCHINA, 51CTO, and Tencent Cloud Developer Community | Preserves Chinese errors, code context, and version clues omitted by general pages. |
| Policy and industry research | MIIT, the Cyberspace Administration of China, and China's National Data Administration | Anchors category, cloud, filing, cybersecurity, and cross-border data explanations. |
| Procurement and public records | China Tendering and Bidding Public Service Platform, MIIT ICP filing query, and the CNCA certification database | Verifies tenders, website filings, or certificate status within each record's stated scope. |
English-language engines (ChatGPT / Perplexity / Gemini)
| Source type | Specific source | Why it may be cited |
|---|---|---|
| Official product records | Vendor docs, API and SDK guides, migration notes, pricing, changelog, trust center, sub-processors, SLA, and status page | Versioned records answer product, commercial, legal, integration, and incident questions when publicly crawlable. |
| Review and category platforms | G2 and Capterra | Exposes category language and reported trade-offs; review date, context, and incentives matter. |
| Comparison and alternative pages | Vendor X-vs-Y and alternative pages, G2 comparison pages, and Capterra category pages | Aligns candidates to explicit criteria; dates, public sources, matched conditions, and neutral wording remain necessary. |
| Practitioner and developer communities | Reddit communities including r/SaaS, r/sysadmin, and r/devops; Hacker News; Stack Overflow | Preserves implementation constraints and failure modes; identity, moderation, commercial ties, and freshness limit proof. |
| Open-source project records | GitHub README files, Releases, Issues, Discussions, and security advisories | Repository history gives version, maintenance, limitation, and issue-resolution evidence for open-source components. |
| Cloud and integration marketplaces | AWS Marketplace, Microsoft AppSource, Salesforce AppExchange, and Google Cloud Marketplace | Corroborates commercial availability and ecosystems; vendor-supplied descriptions do not prove performance. |
| Industry and technical media | TechCrunch, VentureBeat, The New Stack, and InfoWorld | Adds dated reporting on product changes, acquisitions, incidents, and technical analysis. |
Common pitfalls and fixes
Citation gaps often trace to inaccessible facts, stale scope, or mismatched comparisons. Each correction creates inspectable evidence.
Treating docs as an engineering by-product
Issue: The help center lacks version and date labels, conflicts with website terms, or hides core facts behind authentication or client rendering.
Correction: Assign technical and marketing owners; publish version, applicability, and dates; align terms; use crawlable HTML and stable URLs; test access while signed out.
Turning comparison and alternative pages into attack copy
Issue: An X-vs-Y page mixes editions, regions, billing periods, or contract terms and repeats stale competitor claims.
Correction: Define date, market, edition, billing basis, and source per row. Link evidence, label unknowns, explain fit conditions, and schedule review.
Blurring a report, certification, and legal claim
Issue: The trust center calls SOC 2 a certification, turns ISO/IEC 27001 into a privacy-law conclusion, or extends document scope.
Correction: State entity or system, document type, criteria or standard, scope, issuer, period or status, and access method. Describe privacy roles per activity.
Publishing a price without the pricing mechanics
Issue: An entry price omits billable seats, meters, allowances, overages, required modules, currency, term, or commitment.
Correction: Define billing units and conditions. Separate public from negotiated terms, explain the logic without invented figures, and update changed packaging.
Writing use cases without constraints or version context
Issue: A use case omits integration direction, required plan, admin permission, data object, region, release status, or known limitation.
Correction: Attach capabilities to prerequisites, objects, plan and region conditions, version, setup docs, and verification date. Put removed behavior in migration notes.
Measuring branded prompts and a single answer
Issue: A branded description test is treated as category discovery evidence, while mentions, displayed citations, and recommendations are combined.
Correction: Freeze non-branded prompts across the decision chain. Repeat by engine under recorded conditions, retain answers and displayed sources, and separate each result type.
Compliance boundaries
Separate filings, assessments, certifications, and attestation reports. Scope, status, roles, and transfers must match current evidence and data flows.
| Rule source | Do not write | Acceptable wording |
|---|---|---|
| Regulation (EU) 2016/679 (General Data Protection Regulation) | Do not make a blanket GDPR claim, assign one role across all processing, or treat EU hosting as resolving access and transfers. | State roles by purpose, separate customer content from account and marketing data, describe the DPA and sub-processors, and identify the transfer mechanism where applicable. |
| California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and the California Consumer Privacy Act Regulations | Do not copy GDPR roles into CCPA, present CPRA as a separate law, or make sell-or-share claims without checking actual uses. | State by processing context the applicable business, service provider, contractor, or third-party role; describe contractual use limits and consumer requests. |
| Section 5 of the Federal Trade Commission Act; Guides Concerning the Use of Endorsements and Testimonials in Advertising, 16 C.F.R. Part 255; Rule on the Use of Consumer Reviews and Testimonials, 16 C.F.R. Part 465 | Do not invent experiences, disguise employees or agencies as independent reviewers, condition incentives on sentiment, use threats to remove negative reviews, misrepresent displayed-review completeness, or hide material connections. | Use genuine experiences, disclose relationships with the endorsement, preserve qualifications, and solicit reviews without requiring sentiment. |
| AICPA SOC 2® — Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy | Do not call SOC 2 a certification, treat Type 2 as permanent company-wide approval, or extend it to unexamined criteria. | State the independent CPA firm, named system, trust services categories, Type 2 examination period, and report access. |
| ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements | Do not claim product certification for a different entity, site, or management-system scope, or infer privacy-law compliance. | Name the certified organization, scope, edition, certification body, and status; link to available verification. |
| Federal Trade Commission Statement of Policy Regarding Comparative Advertising, 16 C.F.R. § 14.15; Section 43(a) of the Lanham Act, 15 U.S.C. § 1125(a) | Do not mix editions, billing periods, regions, or contracts, present stale pricing as current, or state an unsupported winner. | Compare measurable attributes under aligned conditions; link the public source, state date and limits, and schedule review. |
FAQ
- Which B2B SaaS pages should a marketing team review first for AI visibility?
- Review public docs, API reference, pricing, trust center, changelog, status, comparison, and migration pages. Prioritize from frozen prompts and each engine's displayed sources.
- How should a SaaS company describe SOC 2 and ISO/IEC 27001?
- For SOC 2, state the system, categories, and examination period. For ISO/IEC 27001, state the certified organization, scope, edition, certification body, and status. Neither proves privacy-law compliance.
- Can a SaaS vendor publish X-vs-Y and alternative pages?
- Yes, when market, edition, billing basis, contract conditions, and date align. Link material claims, label unknowns, preserve limits, and revise stale facts.
- Does a profile on G2, Capterra, or Reddit guarantee an AI citation?
- No. Engines, prompts, indexes, and displayed citations change. Archive actual citations and treat source selection as an observed pattern, not a fixed ranking factor.
- What can MaxGrowth verify in a B2B SaaS GEO engagement?
- We verify agreed prompts, source audits, content checks, publication, crawl access, repeated tests, full answers, and displayed citations. We do not promise a particular outcome.
Want to know how AI answers your category today? Start with a free audit.
Get a Free Audit