Zero Data Retention (ZDR)¶
Summary
Zero Data Retention (ZDR) is a bundle of contract terms and provider-side controls under which an LLM provider does not store customer prompts and outputs at rest after the response is returned. It is a baseline requirement for regulated LLM use (healthcare, finance, government). In 2026 the picture split: Anthropic requires 30-day retention for its most capable Covered Models (Fable/Mythos 5.x) and is building customer-held safety logs (Enterprise Frontier Safeguards), OpenAI offers ZDR for frontier models with automated Private Safety Processing, and Amazon Bedrock exposes retention as an explicit account-level mode.
Without ZDR, providers typically keep prompts and outputs for abuse monitoring for up to 30 days, and stateful features (batch, files, server-side conversation state) keep data longer.
ZDR is contractual, not cryptographic
No major AI provider gives cryptographic proof that data was not retained. ZDR is a contractual commitment paired with provider-side engineering, and every provider still retains flagged content or data under legal hold. Self-hosting remains the only path to hard guarantees.
Key Facts¶
| Item | Value |
|---|---|
| What it is | Contract + configuration: no storage of prompts/outputs after the response (per provider scope) |
| Latest policy change (date) | Amazon Bedrock aws_review retention mode (2026-09-04); Anthropic Enterprise Frontier Safeguards announced (2026-09-01) |
| Typical default without ZDR | Up to 30 days abuse-monitoring retention (OpenAI; Anthropic Privacy Center; Groq; Mistral) |
| ZDR by default | Amazon Bedrock (mode default stores nothing for most models), Fireworks open models (Responses API stores by default; checked 2026-09-27) |
| By approval only | Anthropic (per org), OpenAI (per org/project), Azure (modified abuse monitoring), Mistral (paid plans) |
| Floors that survive ZDR | Flagged content (Anthropic up to 2 years), CSAM hits (OpenAI), legal holds, automated review (Azure) |
| Biggest 2026 carve-out | Anthropic Covered Models: 30-day retention since 2026-06-09 on every platform |
| HIPAA | Separate arrangement; Anthropic HIPAA readiness replaces "ZDR for HIPAA" |
| Last verified | 2026-09-27 (Google, Groq, Fireworks, Mistral default via search listings of the official pages) |
How It Works¶
A ZDR request is redacted inside your boundary, processed in provider memory, and dropped; the dashed paths are the carve-outs that remain even inside a ZDR arrangement.
flowchart LR
APP["Your app"] --> DLP["DLP proxy<br/>Presidio / LLM Guard"]
DLP --> GW["AI gateway<br/>LiteLLM / OpenRouter zdr=true"]
GW --> INF["Provider inference<br/>in memory only"]
INF --> GW
INF -.->|"stateful features"| ST[("Batch, Files,<br/>containers")]
INF -.->|"retention-required models"| SR[("30-day safety store")]
INF -.->|"classifier flag / legal hold"| FL[("Flagged content")]
The full data-lifecycle diagrams, blueprints, and threat model are in the Explanation.
ZDR Postures by Provider¶
Providers take different approaches. The detailed, dated matrix with sources is in the Reference.
| Provider | Default retention | ZDR mechanism | How to enable |
|---|---|---|---|
| Amazon Bedrock | None for most models; Covered Models need aws_review (up to 30 days inside AWS) |
Data retention mode none |
PutAccountDataRetention API |
| Anthropic Claude API | API docs: not retained except Covered Models; Claude Code docs: 30 days standard (sources disagree) | ZDR arrangement per organization | Sales / account team |
| OpenAI | Up to 30 days (abuse monitoring logs) | ZDR or Modified Abuse Monitoring | Prior approval, per org/project |
| Azure OpenAI / Foundry | Flagged content stored for human review | Modified abuse monitoring (Limited Access) | Form; managed customers only; verify ContentLogging: false |
| Google Vertex AI | 24 h in-memory cache + abuse logging (checked 2026-09-27) | Disable cache + abuse-monitoring exception | Project config + support request |
| Mistral AI | 30 rolling days (abuse monitoring) | ZDR for stateless endpoints | Support request (paid plans) |
| OpenRouter (gateway) | OpenRouter keeps nothing unless you opt in; upstream varies | provider.zdr: true, account toggles |
Request parameter or settings |
| Groq | Not retained, but logs for troubleshooting/abuse kept up to 30 days (checked 2026-09-27) | Self-serve ZDR toggle | Console > Data Controls |
| Fireworks AI | None by default for open models; Responses API stores unless store=false |
Default | None |
2026 Developments¶
- Anthropic Covered Models (2026-06-09). Claude Fable 5, Fable 5.1, Mythos 5, and Mythos 5.1 require 30-day retention on every platform, including Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry. ZDR orgs get
400 invalid_request_errorunless a workspace enables retention. See Covered Models. - Amazon Bedrock retention modes (2026-06-09,
aws_review2026-09-04). Retention became an account/project setting with modesdefault,none,aws_review,provider_data_share,inherit. - OpenAI ZDR for frontier models (2026-08-21). Paired with Private Safety Processing, which returns only a narrow risk signal to OpenAI; phased rollout.
- Anthropic Enterprise Frontier Safeguards (2026-09-01). Safety logs go to customer-owned S3, Azure Blob, or GCS; flags go to the customer. Eligible customers get interim ZDR on Fable 5/5.1 until it ships (fall 2026).
- HIPAA readiness is self-serve at Anthropic. Standard BAA can be executed in the Console; it is an alternative to ZDR and cannot be disabled once on.
Feature-Level Caveats¶
A provider-level ZDR agreement does not cover every endpoint. The rule of thumb: anything stateful (batch jobs, files, code-execution containers, server-side conversation state, long-lived caches) sits outside ZDR. Highlights:
- Anthropic: Batch (29 days), Files API, code execution (30 days), Agent Skills, MCP connector, Managed Agents, and the Console are outside ZDR; structured outputs cache the JSON schema up to 24 hours; CORS is disabled for ZDR orgs; flagged content can be kept up to 2 years.
- OpenAI: extended prompt caching (
24h) is not ZDR-eligible, andgpt-5.5and later only support24hcache retention; the Videos API is blocked for ZDR/MAM orgs (as of 2026-07-07); CSAM hits are retained regardless. - Claude Code on Claude Enterprise ZDR: cloud sessions, Remote Control, Artifacts, Claude Tag, and
/feedbackare disabled.
Full tables: Anthropic feature eligibility, OpenAI facts.
Evaluation and Impact¶
ZDR removes most provider-side risks: training-data leakage, abuse-monitoring storage, and staff access. It does not protect against your own logging or prompt-injection exfiltration. Pair it with proxy-based PII redaction and a gateway that blocks stateful features. For extreme privacy needs, self-hosting open-weight models (for example Llama 4, DeepSeek, Qwen3) remains the only fully trusted path.
| Fit | When |
|---|---|
| Good fit | Regulated data sent to frontier APIs; legal/contractual bans on vendor storage; minimizing breach and subpoena exposure |
| Poor fit | Workloads that need batch, files, server-side agents, or the newest Covered Models; teams that cannot run a backend proxy (CORS) |
| Alternatives | HIPAA readiness (Anthropic), customer-held logs (EFS), regional inference only, self-hosting |
Two 2026 shifts change the calculus:
- HIPAA no longer requires ZDR at Anthropic. HIPAA readiness (signed BAA + HIPAA-enabled organization) replaces the old "enable ZDR for HIPAA" guidance and unlocks more features because data can be retained with safeguards.
- Frontier-model access and ZDR diverged, then started to reconverge. Covered Models forced a choice between the newest models and no-retention postures; EFS and OpenAI's Private Safety Processing are the providers' attempts to offer both. Until they are generally available, segregate workloads by workspace, account, or subscription.
Topic Map¶
- How-to Guides: verify, configure and audit ZDR with LLM providers.
- Reference: provider retention postures, feature eligibility, configuration keys, audit checklists.
- Explanation: where prompt and output data can persist, provider carve-outs, 2026 safety-retention designs, threat model.
- Ref: ZDR LLM Providers: source note on provider ZDR programs.
Related Topics¶
- Ref: ZDR Across LLM Providers: source note
- AI Platform Engineering: gateways and platform controls around LLM traffic
- AWS and GCP: cloud platforms hosting Bedrock and Vertex AI
- LLM Inference: self-hosted serving for no-third-party deployments
- AI-PDLC and LLM Wiki: agent workflows that send context to external models
- AI Agents comparisons: no comparison page covers ZDR yet
Sources¶
- Anthropic: API and data retention: ZDR scope, Covered Models, HIPAA readiness, feature eligibility (checked 2026-09-25)
- Anthropic: Data retention practices for Covered Models
- Anthropic: Enterprise Frontier Safeguards (2026-09-01)
- Anthropic Privacy Center: ZDR agreement product scope
- Claude Code: Zero data retention and Data usage
- OpenAI: Data controls in the OpenAI platform
- OpenAI: Offering Zero Data Retention for frontier models (2026-08-21)
- AWS: Amazon Bedrock data protection and data retention
- AWS API reference: PutAccountDataRetention
- Microsoft: Data, privacy, and security for Azure OpenAI
- Anthropic: Claude in Microsoft Foundry
- Google Cloud: Vertex AI and zero data retention
- Mistral Help Center: how long inputs and outputs are stored (30 rolling days; checked 2026-09-27 via search listing)
- Groq: Your data in GroqCloud (checked 2026-09-27 via search listing)
- Fireworks AI: Zero Data Retention / data handling (checked 2026-09-27 via search listing)
- Mistral AI: Zero data retention (docs source)
- OpenRouter: Zero Data Retention
- Ref: ZDR Across LLM Providers: source article summary
Questions¶
Open Questions¶
- How do emerging open-weight reasoning models change the break-even math for self-hosting versus relying on ZDR cloud APIs?
- What are the performance impacts of strict proxy-based PII redaction on RAG latency?
- Partly answered: other labs responded to Anthropic's Covered-Models pattern differently. OpenAI chose automated Private Safety Processing with ZDR (2026-08-21), and AWS made human-review retention an explicit
aws_reviewmode. Open: whether Google follows. - Does Enterprise Frontier Safeguards count as "zero retention" for regulators and auditors, given Anthropic's automated systems still analyze the traffic?
- How does OpenAI ZDR interact with
gpt-5.5+ models, which only support24hprompt-cache retention while extended caching is not ZDR-eligible?
Answered Questions¶
- Anthropic's default API retention (not retained vs 30 days) conflicts across its own pages. Answer (2026-09-27): the commercial Privacy Center says API inputs and outputs are deleted "within 30 days of receipt or generation", while the API docs say conversation content is "not retained by default" except Covered Models. Plan for up to 30 days without ZDR; details in Reference.