ZDR Operations & Commands¶
Implementing Zero Data Retention requires continuous verification, strict configuration management, and thorough auditing. These guides are task-oriented; for the facts behind them (eligibility tables, retention periods, mode names) see the Reference, and for the reasoning see the Explanation.
Replace placeholders and check your contract
Values in angle brackets (<resource>, <vpc-id>) are placeholders. Commands were checked against provider API models and docs on 2026-09-25; provider consoles and flags change often.
Verification & Audit Guide¶
A credible ZDR audit establishes the Four Pillars of Evidence: configuration artifacts, negative tests, an environment audit, and contractual proof.
1. Configuration Artifacts¶
Capture proof that ZDR is enabled for every provider, account, organization, and Region you use.
Azure OpenAI¶
After Microsoft approves modified abuse monitoring, the resource's capabilities list includes ContentLogging set to false. The property does not appear at all while abuse-monitoring storage is on.
# Full resource JSON (the command Microsoft documents)
az cognitiveservices account show --name <resource> --resource-group <rg>
# Just the ContentLogging capability
az cognitiveservices account show --name <resource> --resource-group <rg> \
--query "properties.capabilities[?name=='ContentLogging'].value"
# Expected output: [ "false" ] (empty list means abuse-monitoring storage is still on)
Amazon Bedrock¶
Check two things per account and Region: the data retention mode (API added 2026-06-09) and that model invocation logging is not writing prompts to your own CloudWatch or S3.
# Retention mode: expect "none" for strict ZDR
aws bedrock get-account-data-retention --region <region>
# Your own invocation logging: expect no loggingConfig, or one without text/image delivery
aws bedrock get-model-invocation-logging-configuration --region <region>
Anthropic (Claude API)¶
- Screenshot the organization's ZDR confirmation from your account team (ZDR is not visible as a self-serve toggle).
- For each workspace, record Console > Settings > Workspaces > Privacy controls, noting any workspace with 30-day retention enabled for Covered Models.
- For HIPAA-ready orgs, record Console > Settings > Privacy (HIPAA compliance card) and the BAA version accepted.
OpenAI¶
Screenshot the organization or project data-retention setting in the platform dashboard showing ZDR or Modified Abuse Monitoring. Both require prior approval, so keep the approval email with the evidence.
Mistral AI¶
After approval, ZDR appears in Admin Panel > API > Privacy. Screenshot it; if it does not appear, the request has not been processed.
2. Negative Tests¶
Attempt to retrieve data that must not exist, to prove the retention policy is active.
OpenAI¶
Stored chat completions can be retrieved by ID. Under ZDR, store is forced to false, so the lookup fails.
curl https://api.openai.com/v1/chat/completions/<completion-id> \
-H "Authorization: Bearer $OPENAI_API_KEY"
# Expected output: 404 / not found error
Amazon Bedrock¶
Check CloudWatch for model invocation logs. The log group either does not exist or is empty.
aws logs filter-log-events \
--log-group-name "<invocation-log-group>" \
--start-time $(date -d '1 hour ago' +%s000)
# Expected output: empty, or ResourceNotFoundException
Also confirm that a retention-required model is refused under mode none: invoking a Covered Model (for example Claude Fable 5.1) should return an error rather than silently switching modes.
Anthropic¶
From a ZDR workspace, send a request to a Covered Model. Expect 400 invalid_request_error with "your organization or workspace must have data retention enabled". A success means the workspace or org has retention on.
3. Environment Audit¶
Make sure your own infrastructure does not log the data you are protecting from the provider. This is where most real-world leaks happen.
- Web framework request logging: Express, Django, and FastAPI middleware often log full request bodies. Disable it or log only after redaction.
- HTTP client debug logs:
requests(Python) oraxios(Node) can log bodies at DEBUG level. Set WARN or higher in production. - LLM SDK logging: OpenAI and Anthropic SDKs can log prompts at debug level (for example
OPENAI_LOG=debug,ANTHROPIC_LOG=debug). Keep these off in production. - API gateway / load balancer: configure it not to log request bodies.
- Error tracking (Sentry, Datadog): use
before_sendhooks to strip prompt fields from events and traces. - LLM observability tools (LangSmith, Langfuse): they capture full prompts by default. Enable their masking/redaction features explicitly.
- Database query logging: use parameterized queries; do not log full statements containing prompt text.
- WAF / DLP proxy: make sure the proxy is not storing payloads in its own logs.
- Browser storage:
localStorageand network tabs hold unredacted prompts. Redact server-side before data reaches the client where possible. - Coding agents: Claude Code keeps local transcripts in
~/.claude/projects/for 30 days by default (cleanupPeriodDays). Shorten it on machines that handle regulated data.
4. Contractual Proof¶
Collect signed agreements to present during compliance audits:
- BAA (Business Associate Agreement): required for HIPAA.
- DPA (Data Processing Agreement/Addendum): required for GDPR.
- ZDR addendum or amendment: provider-specific record of zero data retention.
- SOC 2 Type II report: downloadable from the provider's trust center.
Commands & Recipes¶
Set Bedrock Account Retention to None¶
Force zero retention for an account in one Region. Models or APIs that require retention (Covered Models, Responses API with store=true) will be refused.
aws bedrock put-account-data-retention --mode none --region us-east-1
aws bedrock get-account-data-retention --region us-east-1
Valid modes are default, none, aws_review, provider_data_share, and inherit (see Bedrock data retention modes). Repeat per Region and per account; AWS publishes an SCP-based pattern for enforcing this across an AWS Organization.
Segregate Covered-Model Traffic¶
For organizations with an Anthropic ZDR arrangement that also need Covered Models (Fable 5/5.1, Mythos 5/5.1), use workspace-level segregation rather than dropping ZDR org-wide:
- Keep the organization default at zero data retention.
- Create one designated workspace and enable 30-day retention in Claude Console > Settings > Workspaces > (workspace) > Privacy controls.
- Issue API keys for that workspace only to the services allowed to use Covered Models.
- In the AI gateway, map model IDs to workspace keys so a developer cannot send regulated data to the retention workspace by accident, for example
claude-fable-5-1routes only with the retention-workspace key, everything else with ZDR keys. - On Azure, provision a separate subscription for Covered-Model access; ZDR-configured subscriptions cannot serve them.
- On Bedrock, set
aws_reviewonly on a dedicated account or project, not on the account that handles regulated traffic. - Re-check eligibility when Enterprise Frontier Safeguards reaches your account: eligible customers get interim ZDR on Fable 5/5.1 until then.
Route Claude Code Traffic to the ZDR Organization¶
ZDR applies only to requests that authenticate into the ZDR-enabled organization. Deploy managed settings through MDM so developers cannot log in with personal accounts:
With forceLoginOrgUUID set, Claude Code also blocks ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, and apiKeyHelper credentials at startup, because it cannot verify their organization. Cloud-provider sessions (Bedrock, Agent Platform, Foundry) are not blocked; restrict those with cloud IAM.
OpenAI Stateless Request¶
Once ZDR is enabled at the org or project level, store is always treated as false. Setting it explicitly documents intent and keeps the request stateless on non-ZDR projects too. With the Responses API, request encrypted reasoning so multi-turn reasoning works without server-side state.
curl https://api.openai.com/v1/responses \
-H "Authorization: Bearer $OPENAI_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "<zdr-eligible-model>",
"store": false,
"include": ["reasoning.encrypted_content"],
"input": "Hello"
}'
Chat Completions equivalent: send "store": false with messages. Avoid extended prompt caching (prompt_cache_retention: "24h") on ZDR workloads; it is not ZDR-eligible.
AWS Bedrock PrivateLink Setup¶
Keep all Bedrock traffic within the AWS network.
aws ec2 create-vpc-endpoint \
--vpc-id <vpc-id> \
--service-name com.amazonaws.<region>.bedrock-runtime \
--vpc-endpoint-type Interface \
--subnet-ids <subnet-id> \
--security-group-ids <sg-id>
AWS Bedrock Guardrails (PII Redaction)¶
Configure a guardrail to anonymize emails and block SSNs before they reach the model.
aws bedrock create-guardrail \
--name "pii-guardrail" \
--blocked-input-messaging "Blocked" \
--blocked-outputs-messaging "Blocked" \
--sensitive-information-policy-config '{
"piiEntitiesConfig": [
{"type": "EMAIL", "action": "ANONYMIZE"},
{"type": "US_SOCIAL_SECURITY_NUMBER", "action": "BLOCK"}
]
}'
Azure OpenAI Private Endpoint¶
Keep traffic to Azure OpenAI off the public internet.
az network private-endpoint create \
--name openai-pe \
--resource-group <rg> \
--vnet-name <vnet> \
--subnet <subnet> \
--private-connection-resource-id <openai-resource-id> \
--group-id account \
--connection-name openai-conn
# Disable public access
az cognitiveservices account update \
--name <resource-name> \
--resource-group <rg> \
--public-network-access Disabled
OpenRouter ZDR Routing¶
Route a request only to endpoints with a ZDR policy. If no eligible endpoint exists for the model, the request fails instead of falling back.
curl https://openrouter.ai/api/v1/chat/completions \
-H "Authorization: Bearer $OPENROUTER_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "<openrouter-model-slug>",
"messages": [{"role": "user", "content": "Hello"}],
"provider": {
"zdr": true,
"data_collection": "deny"
}
}'
zdr: true restricts to zero-retention endpoints; data_collection: "deny" only excludes providers that train on data, so use it as an extra filter, not a substitute. For fleet-wide enforcement, turn on the per-model-group ZDR toggles in OpenRouter privacy settings or on a guardrail (enforce_zdr_* fields). List eligible endpoints with GET https://openrouter.ai/api/v1/endpoints/zdr.
Request Mistral ZDR¶
- Confirm you are on a paid plan and only need stateless endpoints (chat, FIM, embeddings, moderation, classification, OCR, speech).
- Contact Mistral support through the ZDR Help Center article with your business reason.
- After approval, verify in Admin Panel > API > Privacy.
- If data location also matters, send traffic to
api.eu.mistral.aiorapi.us.mistral.ai(1.1x price). Regional inference and ZDR are separate controls.
Self-Hosted Quickstarts¶
Deploy open-weight models internally when no third party may hold your data.
vLLM Quickstart¶
Best for production serving and high-concurrency workloads.
pip install vllm
# Serve a model with an OpenAI-compatible API
vllm serve deepseek-ai/DeepSeek-R1-Distill-Qwen-32B \
--tensor-parallel-size 1 \
--gpu-memory-utilization 0.8 \
--enforce-eager \
--port 8000
# Call it like OpenAI
curl http://localhost:8000/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{
"model": "deepseek-ai/DeepSeek-R1-Distill-Qwen-32B",
"messages": [{"role": "user", "content": "Hello"}]
}'
In current vLLM (0.30.0 on PyPI, checked 2026-09-25) per-request logging is opt-in through --enable-log-requests (default off). Leave it off for ZDR workloads; older releases logged requests unless you passed --disable-log-requests.
Ollama Quickstart¶
Best for local development or simple single-node deployments.
# Install
curl -fsSL https://ollama.com/install.sh | sh
# Pull and chat with Llama 4 Scout (tag llama4:scout)
ollama run llama4:scout
# OpenAI-compatible API (the installer starts the server; otherwise run: ollama serve)
curl http://localhost:11434/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{
"model": "llama4:scout",
"messages": [{"role": "user", "content": "Hello"}]
}'
Sources¶
- Microsoft: verify abuse-monitoring storage is off
- botocore Bedrock service model (
PutAccountDataRetention, guardrail enums) - Anthropic: API and data retention
- Claude Code: Zero data retention and Authentication
- OpenAI OpenAPI spec (
store,include,prompt_cache_retention) - OpenRouter: Zero Data Retention
- Mistral ZDR docs source