OpenAI’s API documentation says eligible customers can use Zero Data Retention, which excludes customer content from abuse-monitoring logs and avoids retaining customer content as application state on eligible endpoints. The case’s evidence title reports that OpenAI is testing a “Private Safety Processing” architecture, apparently intended to preserve safety monitoring without storing prompts, but the supplied snippets do not establish how it works, when it will deploy, or the claimed contrast with Anthropic’s logging requirements. ZDR is requestable rather than a general default and does not by itself establish regulatory compliance.
A consequential provider is testing an architecture that converges with Scott’s existing privacy-by-structure approach: stateless processing, sensitive-data minimisation, and safety or observability without durable raw-prompt retention. If deployed, it could directly affect provider selection and regulated-workload design for his active AI appliance and gateway work, while offering a dated-receipts publishing opportunity; however, the evidence does not yet establish OpenAI’s mechanism, deployment date, or equivalence to Scott’s tokenised boundary.
ip:framework.siloosip:concept.stateless-executionip:source.observability-for-agentic-systems-what-to-log-how-to-redact-how-to-debug-ebookdev:project.appliancedev:concept.privacy-tokenized-agent-boundarydev:concept.ephemeral-source-ai-reviewradar:concept.privacyradar:concept.ai-privacyradar:concept.llm-apisradar:concept.enterprise-ai
queries asked of Scott's wikis
- privacy-preserving LLM safety monitoring without prompt logs
- zero-retention API architecture for regulated workloads
- customer-controlled data retention in AI systems
- LLM gateway logging and sensitive-data boundaries
- local models versus hosted APIs for data sovereignty
- stateless RAG and agent deployments
2026-08-31T09:29:18Z
The early-customer ZDR pilot remains established, but repeated checks have produced no technical details, eligibility expansion, verified pricing, or production adoption. The episode has faded beyond its active horizon and should be reopened only on a concrete first-party rollout or implementation artifact.
2026-08-29T08:31:15Z
The refreshed discussion adds no reliable evidence on API ZDR pricing, eligibility, adoption, or the privacy-preserving safety mechanism; it remains repetitive and category-confused. The early-customer pilot is established, but broader deployment and architecture claims remain unresolved.
2026-08-28T19:37:35Z
The refreshed discussion remains anecdotal and conflates business-plan privacy, intermediaries and API-level ZDR; it adds no reliable evidence on pricing, eligibility, adoption or technical architecture. The pilot is established, but broader deployment and privacy-preserving cross-interaction monitoring remain unverified.
2026-08-28T12:27:41Z
The refreshed comments add no reliable pricing, eligibility, adoption, or technical evidence and continue to conflate business-plan privacy terms with API ZDR access. The pilot remains established, but broader deployment and the privacy-preserving safety architecture remain unverified.
2026-08-28T09:30:51Z
The comment refresh adds no reliable pricing, eligibility, adoption, or technical evidence; it remains repetitive amplification of an unresolved distinction between API ZDR and business-plan access. The early-customer pilot is established, but broader deployment and the privacy-preserving safety architecture remain unverified.
2026-08-28T07:29:30Z
The refreshed comments remain anecdotal and category-confused: neither the Azure mention nor the disputed business-plan claim establishes equivalent API ZDR access, pricing, or eligibility. The pilot remains established, but broader deployment and the privacy-preserving safety architecture are still unverified.
2026-08-28T04:29:11Z
The refreshed discussion adds no reliable pricing, eligibility, or technical evidence; it remains a category-confused dispute between undocumented API sales terms and a business-plan claim. The early-customer test is established, but broader deployment and the privacy-preserving safety mechanism remain unverified.
2026-08-28T02:30:26Z
A brief Reddit reply disputes the reported $50,000 minimum but appears to reference a per-seat business plan and provides no evidence that it grants equivalent API ZDR access. Pricing and eligibility therefore remain ambiguous, with no new support for broader deployment or the underlying safety architecture.
2026-08-28T00:28:13Z
An anonymous customer report introduces a potentially material $50,000 annual access barrier, narrowing the practical value of ZDR for smaller deployments but not validating the safety architecture or broader rollout. The pricing claim remains uncorroborated and may reflect account-specific sales terms.
2026-08-28T00:23:27Z
evidence attached: reddit.post.1w0a89v — The reported $50,000 annual minimum is concrete evidence that OpenAI zero-retention access may carry a material enterprise cost barrier.
2026-08-27T00:30:42Z
The established early-customer test still supports direction of travel, but no new evidence shows broader deployment or validates cross-interaction safety monitoring without retained prompts. The case remains cold pending technical details, expanded eligibility, or production adoption.
2026-08-25T00:27:57Z
Repeated checks add no evidence beyond the established early-customer pilot; broader deployment and the privacy-preserving monitoring mechanism remain unverified. The case is cold but still open pending technical details, eligibility expansion, or production adoption.
2026-08-23T00:22:41Z
No new evidence has arrived beyond repeated engagement checks, so the established early-customer pilot still does not demonstrate broader deployment or validate the privacy-preserving safety mechanism. The case remains relevant but cold pending first-party technical details, eligibility expansion, or production adoption.
2026-08-20T23:35:19Z
The latest HN item is another pointer to OpenAI’s already-known announcement, not independent evidence of deployment or the safety architecture’s properties. The early-customer test remains established, while rollout, eligibility and cross-interaction monitoring without retained prompts remain unresolved.
2026-08-20T23:23:04Z
evidence attached: hn.story.49381251 — This independently reported OpenAI announcement directly supports the open hypothesis about zero-retention safety monitoring for privacy-sensitive API workloads.
2026-08-20T21:31:42Z
The Reddit post is amplification of OpenAI’s already-known announcement, not an independent line of evidence for deployment or the underlying safety mechanism. The test is established, but architecture, eligibility, security properties and rollout remain unresolved.
2026-08-20T21:23:22Z
evidence attached: reddit.post.1vtvhgp — The linked OpenAI announcement independently corroborates movement toward zero-retention safety monitoring and adds Anthropic’s customer-controlled retention context.
2026-08-19T20:42:36Z
OpenAI’s first-party announcement turns the zero-retention offering from reported testing into a concrete access and retention change for frontier-model API workloads. The broader Private Safety Processing mechanism—especially cross-interaction misuse detection without retained prompts—remains unverified, so the architecture hypothesis is not yet corroborated.
2026-08-19T20:23:34Z
evidence attached: hn.story.49366377 — OpenAI's first-party announcement directly confirms progress toward a zero-data-retention offering for frontier-model API use.
2026-08-19T17:53:56Z
No substantive evidence has arrived beyond trivial engagement growth; the reported customer test remains single-source testimony without a first-party mechanism, access details, or deployment timeline.
2026-08-19T17:48:25Z
grounded: converges/high — A consequential provider is testing an architecture that converges with Scott’s existing privacy-by-structure approach: stateless processing, sensitive-data min
2026-08-19T17:46:03Z
origin walked (codex/luna, conf 0.78): anchor hn.story.49364226 -> echo.other.e34b4de5c8 by Axios
2026-08-19T17:44:51Z
case created — The reported provider-level change could materially alter the privacy and abuse-monitoring tradeoffs of production LLM APIs.