Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
zdr — Curated guide to zero-data-retention configurations for LLM APIs. Covers provider-specific ZDR endpoints, threat models, compliance mappings, and self-hosting patterns for engineers in regulated industries. | Kitploit
Tools/GitHubGitHub/abubakarsiddik31/zdr
Data ExfiltrationCloud SecurityPrivacyThreat IntelligenceLearning & EducationCurated Resources
GitHubabubakarsiddik31/zdr

zdr

Curated guide to zero-data-retention configurations for LLM APIs. Covers provider-specific ZDR endpoints, threat models, compliance mappings, and self-hosting patterns for engineers in regulated industries.

View Repository
261375 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Zero Data Retention (ZDR) for LLM Providers

License: Apache 2.0 Maintenance PRs Welcome

Last updated: April 2026

A practical guide to keeping your data private when using LLM APIs. Covers zero-retention endpoints, self-hosting, compliance requirements, and data protection patterns for engineers in regulated industries.


Table of Contents

  • Which Approach Is Right for Me?
  • Threat Model
  • Provider Reference
    • OpenAI
    • Anthropic
    • Google Vertex AI
    • Azure OpenAI
    • AWS Bedrock
    • Mistral AI
    • Groq
    • Fireworks AI
    • Together AI
    • Cohere
    • Hugging Face Inference Endpoints
    • Replicate
  • Gateways & Routers
  • Chinese & International Providers
  • Self-Hosting Open-Weight Models
  • Global Comparison Table
  • Compliance Mapping
  • Data Protection Beyond ZDR
  • Verification & Audit Guide
  • Architecture Blueprints
  • Contributing

Which Approach Is Right for Me?

"Zero-retention" is not a single feature — it is a bundle of technical controls + contract terms ensuring customer content (prompts, outputs, files) is not stored at rest by the vendor. Different approaches offer different trade-offs:

flowchart TD
    Start(["Need Private AI?"]) --> Q1{"Can you\nself-host?"}

    Q1 -->|"Yes, have GPUs"| SH["Self-Host Open Weights\n(Llama 4 · DeepSeek · Mistral · Qwen)"]
    Q1 -->|"Yes, CPU only"| OL["Ollama + Quantized Models\n(7B–14B on consumer hardware)"]
    Q1 -->|No| Q2{"Need frontier\nmodel quality?"}

    Q2 -->|Yes| Q3{"Regulatory\nrequirements?"}
    Q2 -->|No| Q4{"Budget\nconstrained?"}

    Q3 -->|"HIPAA / FedRAMP"| Cloud["Azure OpenAI · AWS Bedrock\n+ Private Endpoints + BAA"]
    Q3 -->|"Multi-provider"| GW["OpenRouter · Cloudflare AI Gateway\nwith ZDR routing"]
    Q3 -->|"Single provider OK"| Direct["Direct ZDR Contract\n(OpenAI · Anthropic · Google)"]

    Q4 -->|Yes| Budget["Fireworks · Together AI\n(open-weights, low cost, ZDR included)"]
    Q4 -->|"Not really"| Fast["Groq · Fireworks · Together\nZDR toggle in dashboard"]

    style Start fill:#4a90d9,stroke:#2c5f8a,color:#fff
    style SH fill:#2ecc71,stroke:#1a9c54,color:#fff
    style OL fill:#2ecc71,stroke:#1a9c54,color:#fff
    style Cloud fill:#e67e22,stroke:#b3611a,color:#fff
    style GW fill:#9b59b6,stroke:#7a3d92,color:#fff
    style Direct fill:#3498db,stroke:#2471a3,color:#fff
    style Budget fill:#1abc9c,stroke:#148f77,color:#fff
    style Fast fill:#1abc9c,stroke:#148f77,color:#fff

Approach Comparison

ApproachPrivacy StrengthModel QualityOperational CostSetup Complexity
Self-hosted (air-gapped)StrongestOpen-weight onlyHardware + opsHigh
Self-hosted (VPC)Very strongOpen-weight onlyCloud GPU costMedium
Cloud ZDR + Private LinkStrong (contractual)Frontier modelsAPI pricingLow-Medium
SaaS ZDR APIGood (contractual)Frontier modelsAPI pricingLow
Gateway with ZDR routingGood (delegated)Multi-providerAPI + gateway feeLow

Threat Model

Before choosing an approach, understand what you're protecting against:

ThreatDescriptionMitigated By
Training data leakageYour prompts/outputs used to train the provider's modelsZDR contract, API-tier (not free-tier), self-hosting
Abuse monitoring retentionProvider stores prompts for safety review (often 30 days)ZDR/MAM opt-out, self-hosting
Employee accessProvider staff can view your data during incident responseZDR + BYOK encryption, self-hosting
Subpoena / legal discoveryGovernment or legal requests to the provider for your dataSelf-hosting, data residency controls, no-retention contract
Breach at providerProvider's systems compromised, your data exfiltratedNo-retention (nothing to steal), self-hosting, encryption at rest
Your own loggingYour infra (proxies, APM, error trackers) logs sensitive promptsDLP proxy, log redaction, audit your pipeline
Prompt injection exfiltrationMalicious input causes LLM to leak data via tool callsOutput scanning, least-privilege tools, sandboxing

Data Lifecycle: Where Your Prompts Go

flowchart LR
    User["User Input"] --> App["Your App"]

    subgraph YourInfra["Your Infrastructure"]
        App --> Logs1["App Logs ⚠️"]
        App --> DLP["DLP / PII Proxy"]
        DLP --> GW["API Gateway"]
        GW --> Logs2["Gateway Logs ⚠️"]
    end

    subgraph Provider["LLM Provider"]
        GW --> Inference["Model Inference\n(in-memory)"]
        Inference --> Abuse["Abuse Monitor\n(0–30 day retention)"]
        Inference --> Training["Model Training\n(opt-out or ZDR)"]
    end

    Inference --> Response["Response"]
    Response --> App

    style Logs1 fill:#e74c3c,stroke:#c0392b,color:#fff
    style Logs2 fill:#e74c3c,stroke:#c0392b,color:#fff
    style Abuse fill:#f39c12,stroke:#d68910,color:#fff
    style Training fill:#e74c3c,stroke:#c0392b,color:#fff
    style DLP fill:#2ecc71,stroke:#1a9c54,color:#fff
    style Inference fill:#3498db,stroke:#2471a3,color:#fff

Red = risk points where data can be retained. Green = protection layer. ZDR eliminates the provider-side risks; DLP/proxy eliminates your-side risks.


Provider Reference

OpenAI

Official docs: Data Controls

  • Control Name: Zero Data Retention (ZDR) / Modified Abuse Monitoring (MAM)
  • Default retention: Prompts stored up to 30 days for abuse monitoring
  • How to enable ZDR: Enterprise sales approval required → Dashboard: Settings → Organization → Data Retention → configure at org or project level
  • ZDR behavior: The store parameter is always treated as false, even if set to true in requests
  • MAM alternative: Excludes customer content from abuse monitoring logs but keeps the store parameter functional — for orgs that need data retention but reduced monitoring

ZDR-Eligible Endpoints: /v1/chat/completions, /v1/responses, /v1/images/*, /v1/embeddings, /v1/audio/*, /v1/moderations, /v1/completions, /v1/realtime

NOT ZDR-Eligible: Assistants API (/v1/assistants, /v1/threads, /v1/vector_stores), Conversations API, Files, Fine-tuning, Batches, Evals, Background mode (/v1/responses with background: true), Hosted containers (Code Interpreter)

Additional Controls:

  • Data Residency: Available for EU (eu.api.openai.com), AU (au.api.openai.com) — requires ZDR amendment, 10% cost uplift
  • Enterprise Key Management (EKM): Encrypt application state using your external KMS (AWS, GCP, Azure)
  • Extended prompt caching: Stores GPU-local tensors with 24-hour expiry — incompatible with strict ZDR
Download Tool