> ## Documentation Index
> Fetch the complete documentation index at: https://docs.opper.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Enforce zero data retention (ZDR)

> Zero data retention on Opper: store no prompts or outputs at Opper and allow only providers that neither train on nor log your content. Choose ZDR routes per call on any plan, or enforce ZDR org-wide with Rules.

Zero data retention (ZDR) on Opper has two parts, and you can enforce both for
your whole organization:

* **Opper stores no content.** With an enabled 0-day
  [Opper retention](/control-plane/rules/retention) rule, Opper stores no
  prompts, outputs, or traces for any project. It keeps only a usage record
  with no prompts or responses in it.
* **The provider neither trains on nor logs your content.** The **Zero data retention** provider data
  policy in [Model access](/control-plane/rules/model-access) allows only model
  routes whose provider neither trains on nor logs request or response content.
  A call to any other route is refused with `403` before the request leaves
  Opper.

The two settings are independent: turning Opper tracing off does not restrict
providers, and the provider policy does not turn tracing off. Set both.

## What each plan includes

| | Gateway | Control Plane | Enterprise |
| - | - | - | - |
| **Opper storage** | Usage metadata only. No prompts, outputs, or traces are stored. | Upgrading creates a 7-day organization retention rule, so traces are stored for 7 days. Set 1 to 30 days, or set 0 days to turn tracing off, for the organization or a project. | Custom retention. |
| **Provider ZDR** | Choose a ZDR route in each call. Nothing stops another call from using a route that logs. | Enforced org-wide by a Model access rule. Other routes are refused. | Enforced org-wide, with custom terms. |

Rules, including retention and model access, are a Control Plane feature. On the
Gateway plan you get ZDR by choosing the route in every call; see
[Choose a ZDR route per call](#choose-a-zdr-route-per-call).

## Enforce ZDR for your organization

In the [Opper platform](https://platform.opper.ai), open **Rules**:

<Steps>
  <Step title="Turn Opper tracing off">
    In **Opper retention**, switch tracing **Off** and save. This leaves the
    organization with an enabled **0-day** rule: new calls store no traces, and
    projects cannot turn tracing back on. If the toggle already shows Off
    because the organization rule is missing or disabled, turn it on and off
    again in the draft before saving, so that an enabled 0-day rule is saved.
  </Step>

  <Step title="Require zero data retention from providers">
    In **Model access**, set **Provider data policy** to **Zero data
    retention**. This selects **No training** and **No logging**. Check the
    match counter to see which models remain, then select **Save changes**.
  </Step>

  <Step title="Optional: require No provider moderation">
    Some providers run content moderation classifiers that can retain flagged
    content. **No provider moderation** excludes them, and needs a signed
    agreement with Opper first. See
    [Arrange approval for No provider moderation](/control-plane/rules/model-access#arrange-approval-for-no-provider-moderation).
  </Step>
</Steps>

Both rules apply from the next request. To manage them from code, use the
[Management API](/control-plane/management-api#manage-rules-from-code).

## What ZDR means, term by term

Providers describe data handling in different words. This is how common terms
map to what Opper records for each route and checks at request time:

| Term you may see | On Opper | Allowed under the ZDR policy |
| - | - | - |
| No training on your data | **No training** | Yes, required |
| Request or response logging | **No logging** means the provider keeps no content in logs | Only routes with no logging |
| Abuse monitoring (for example, 30-day retention for abuse review) | Recorded as `abuse_monitoring` logging | No, it fails **No logging** |
| Content moderation | Recorded separately. **No provider moderation** is its own requirement. | Yes, unless you also require **No provider moderation** |
| Prompt caching | Recorded separately as the route's caching | Yes; **No logging** does not cover caching |

For example, in Opper's catalog in September 2026:

| Route | Where inference runs | Training | Logging | Under the ZDR policy |
| - | - | - | - | - |
| `anthropic/claude-sonnet-5` | United States | No | Abuse monitoring | Refused |
| `openai/gpt-5.5` | United States | No | Abuse monitoring | Refused |
| `aws/claude-sonnet-4-6-eu` | Sweden | No | None | Allowed |
| `azure/gpt-5.5` | Sweden | No | None | Allowed |
| `mistral/mistral-large-2512` | France | No | None | Allowed |

A few providers require a signed agreement before your organization can call
their ZDR routes, such as `azure-zdr` and `vertexai-zdr`. See
[Routes that require an agreement](/control-plane/rules/model-access#routes-that-require-an-agreement).

### What ZDR does not cover

* **Provider caching.** Some routes cache prompts implicitly. The route's
  caching is recorded separately and **No logging** does not exclude it.
* **Content kept for moderation.** Routes that run provider moderation may
  retain flagged content. Require **No provider moderation** to exclude them.
* **Opper's usage record.** Opper keeps a record of each call's cost, tokens,
  latency, status, provider, model, and any `X-Opper-Tags` for 5 years, for
  billing. It contains no prompts or responses, so keep personal data out of
  tags. See
  [usage metadata](/control-plane/rules/retention#usage-metadata-is-retained-separately).
* **Services outside Opper.** Tools and services your application calls
  directly keep their own retention.

A 0-day Opper retention rule also changes what Opper does with files and
caching in its scope: file uploads are rejected, existing files are deleted
after you confirm, and response caching is skipped. See
[Files and response caching](/control-plane/rules/retention#files-and-response-caching).

## Fallbacks and pools under ZDR

Opper never falls back to a route that fails your policy. A bare model name
such as `claude-sonnet-5` runs only on the providers in its pool that pass, and
a pinned route such as `anthropic/claude-sonnet-5` that fails is refused with
`403` rather than switched. Pools in dynamic routes and `models` fallback lists
skip failing entries in the same way; a Model node in a dynamic route instead
ends the route with `403`. See
[What model access covers](/control-plane/rules/model-access#what-model-access-covers)
for each case and
[What a blocked call returns](/control-plane/rules/model-access#what-a-blocked-call-returns)
for the error bodies.

## Find routes that qualify

* **Query the catalog.** `GET /v3/models` needs no API key. `training=no` with
  `logging=none` is the same filter as the ZDR policy, so this returns the
  LLM routes the policy allows (`limit=0` returns every match; `total` gives
  the count). Routes marked **Agreement required** still need the agreement:

  ```bash theme={null}
  curl "https://api.opper.ai/v3/models?type=llm&training=no&logging=none&limit=0"
  ```

  Each model's `compliance` object records its `training`, `logging`,
  `moderation`, and `caching`.
* **Browse:** [opper.ai/models](https://opper.ai/models) labels each route
  **ZDR**, **monitored**, or **retained**. The labels are close to the policy
  but not identical: the policy checks training and request logging, while the
  labels also count content a provider can hold for moderation. Some routes
  labelled monitored, such as Azure routes, meet the policy. Use the
  query above for the exact set the policy allows.
* **Check your own rules.** With your API key, add `include=policy` to see
  whether each model is allowed for your organization and why not, or
  `include=route` for the evidence behind each route's data-handling record.

## Choose a ZDR route per call

Without rules, on any plan, you get provider-side ZDR on a call by naming a
route that meets it, for example `mistral/mistral-large-2512`, which neither
trains on nor logs your content and runs no provider moderation:

```bash theme={null}
curl https://api.opper.ai/v3/compat/chat/completions \
  -H "Authorization: Bearer $OPPER_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model": "mistral/mistral-large-2512", "messages": [{"role": "user", "content": "Hello"}]}'
```

On the Gateway plan Opper stores no prompts or outputs either. On Control
Plane, Opper still keeps the trace for your retention period (7 days after
upgrading) unless you set it to 0 days. What per-call routing cannot do is stop
a different call from naming a route that logs. For that, enforce the policy
with a Model access rule.

## Related

<CardGroup cols={2}>
  <Card title="Keep AI inference in the EU" icon="earth-europe" href="/control-plane/eu-data-residency">
    Enforce EU-only inference and storage locations.
  </Card>

  <Card title="Model access" icon="scale-balanced" href="/control-plane/rules/model-access">
    Every allowlist field and provider data requirement.
  </Card>

  <Card title="Opper retention" icon="database" href="/control-plane/rules/retention">
    Turn trace storage on or off and set how long traces are kept.
  </Card>

  <Card title="Security" icon="shield" href="/overview/security">
    Certifications, hosting, DPA, and sub-processors.
  </Card>
</CardGroup>
