Zero Data Retention (ZDR) for LLM Providers¶
This is a reference note based on the article "Zero Data Retention (ZDR) for LLM Providers" by Abu Bakar Siddik. The takeaways below summarize the article as written; they are not updated when provider policies change.
Currency check (2026-09-25)
The article is dated 2026-04-18 in its search-engine listing (checked 2026-09-27). Several provider claims in it are now superseded; the current, dated facts are in the Reference:
- Anthropic "7 days default retention" reflects a 2025 policy. Anthropic's pages now disagree (API docs: not retained by default; Claude Code docs: 30 days), and Covered Models (Fable/Mythos 5.x) require 30-day retention even under ZDR since 2026-06-09.
- AWS Bedrock is still no-retention by default for most models, but since 2026-06 retention is an explicit account mode, and Covered Models need
aws_review(up to 30 days inside AWS). - OpenRouter:
provider.data_collection: "deny"only excludes providers that train on data. Strict ZDR routing usesprovider.zdr: true. - Azure modified abuse monitoring is limited to customers managed by a Microsoft account team or in an eligible program.
Key Takeaways¶
- Zero Data Retention (ZDR) is a bundle of technical controls and contract terms that make sure that customer content (prompts, outputs, files) is not stored at rest by the vendor. It is critical for enterprise adoption of LLMs in regulated sectors (Healthcare, Finance, Government) to move from experimental scripts to production systems.
- Threat Model: ZDR mitigates risks like training data leakage, abuse monitoring retention, employee access, subpoena/legal discovery, and breaches at the provider. But it does not mitigate risks from your own logging or prompt injection exfiltration. Those require proxy-based redaction and sandboxing.
- Approaches:
- Self-hosted (air-gapped): Strongest privacy, open-weight only, high ops cost.
- Self-hosted (VPC): Very strong privacy, open-weight only, medium ops cost.
- Cloud ZDR + Private Link: Strong (contractual), frontier models, low/medium setup.
- SaaS ZDR API: Good (contractual), frontier models, low setup.
- Gateway with ZDR routing: Good (delegated), multi-provider, low setup.
- Provider Policies:
- OpenAI: ZDR/MAM requires enterprise sales approval.
storeparameter is always treated asfalsewhen ZDR is on. - Anthropic: ZDR Arrangement via enterprise contract. 7 days default retention (not for training).
- AWS Bedrock & Fireworks AI: ZDR by default. No prompts/completions logged without explicit opt-in.
- Google Vertex AI: Abuse monitoring exception via support/invoiced billing.
- OpenRouter: ZDR provider routing can be enforced per-request via
provider.data_collection: "deny". - Compliance: For HIPAA, a BAA is required (available from Azure, AWS, Google, Anthropic Enterprise, Fireworks, Together).
- Verification: ZDR audits require four pillars of evidence:
- Configuration Artifacts (for example, Azure ContentLogging=false)
- Negative Tests (for example, an attempt to retrieve a completion must fail)
- Environment Audit (checking proxy/logging config for PII)
- Contractual Proof (BAA, DPA, SOC 2)
Reference Context¶
- Article outlines architectural blueprints for Cloud ZDR + Private Network, Self-Hosted Production Stack, and Gateway-Based Multi-Provider ZDR.
- Data protection beyond ZDR emphasizes early PII redaction (using Presidio, LLM Guard, AWS Bedrock Guardrails) before data leaves the network.