OpenAI zero data retention for frontier models. https://openai.com/index/offering-zero-data-retention-for-frontier-models/ OpenAI platform data controls. https://developers.openai.com/api/docs/guides/your-data
Every claim in this section is dated September 2026 and should be re-verified before use. Provider terms changed at least twice during 2026.
The procedure takes about twenty minutes per provider and should run quarterly.
Go to the provider's own documentation rather than a summary, a comparison article, or an analyst note, all of which lag. Find four things: the retention period for API traffic, whether API data is used for training by default, which regions process the request, and whether zero data retention is available and on what terms. Read the enterprise or commercial terms rather than the consumer privacy policy, because they frequently differ and only one of them governs your API traffic.
Record the URL, the date, and the exact wording for each of the four. Wording matters more than summary here: "we do not train on your data" and "we do not train on your data by default" are different commitments, and so are "retained for 30 days" and "retained for up to 30 days for abuse monitoring". Put the record next to your data flow record from Chapter 17, so an auditor asking about provider terms gets an answer with a date attached.
Finally, check whether the terms you rely on are contractual or documentary. A statement in documentation can change without notice. A term in your agreement cannot.
Consistent across independent practitioner sources, presented in Chapters 12 to 13 as accepted practice rather than as a cited finding: layered detection, redaction on both request and response, self-hosted redaction driven by versioned policy, avoiding a second LLM as the detector, keeping the token vault outside model reach, and minimising at source first.
https://techcommunity.microsoft.com/blog/azuredevcommunityblog/introducing-pii-shield-a-privacy-proxy-for-every-llm-call/4514726 https://blog.logrocket.com/build-local-ai-proxy-redact-pii-before-llms/ https://predictionguard.com/blog/pii-detection-redaction-llm-pipelines-regulated-industries https://www.gravitee.io/blog/how-to-prevent-pii-leaks-in-ai-systems-automated-data-redaction-for-llm-prompt
ISO 13616 — IBAN structure and the mod-97 check. NIST SP 800-38G — format-preserving encryption modes, with documented small-domain caveats. NIST AI RMF — referenced in practitioner guidance as the mapping target for audit logs.
Two categories were excluded rather than softened.
Vendor accuracy claims presented without a dataset. A figure such as "near-99% precision" from vendor testing contradicts the independent benchmarks in this appendix and is exactly the kind of claim Chapter 4 exists to examine. Where such figures appear in the book, they are labelled as vendor claims and used as the subject of the argument.
Per-vendor retention comparison tables. These were stale within a quarter throughout 2026. Chapter 16 gives the structural point and one named example instead.
Download the full PDF for free?
Free download — no account required