Zero Data Retention: Your Data Stays Yours, Even with AI
When RiskForce moved every tenant to GovCloud, we made a fundamental promise: your data resides in a sovereign, US-based environment meticulously engineered for the most stringent compliance requirements. Today, we're extending that unwavering commitment to one of the most sensitive areas of any modern platform – the AI features you rely on daily.
RiskForce enforces Zero Data Retention (ZDR) across all AI capabilities within our platform. This post will demystify what ZDR means and illuminate its critical importance for organizations managing compliance, vulnerability, and security data.
What Exactly Is Zero Data Retention (ZDR)?
When you interact with an AI feature – whether asking Ava a question, generating a narrative, or analyzing a finding – your request is processed by an AI model. Under a Zero Data Retention configuration, the model provider processes your request and then retains absolutely nothing.
This means:
- Your prompts and the AI's responses are not stored after the request is completed.
- They are not used to train or improve the provider's models.
In essence, the AI answers your question and then, immediately, "forgets" it ever saw it.
How RiskForce Implements ZDR
At RiskForce, ZDR isn't an optional setting or a hidden configuration; it's a foundational principle enforced at our AI gateway:
- System-Driven AI is Always Protected: Any AI feature where RiskForce selects the underlying model – encompassing the everyday AI capabilities throughout the platform – operates exclusively through providers configured for Zero Data Retention.
- Filtered Model Choices: We proactively filter out any AI models or vendors that do not explicitly support Zero Data Retention, ensuring that only compliant options are available.
- Protection-First Routing: Behind the scenes, our system intelligently routes requests to the compliant endpoint that best preserves Zero Data Retention. This guarantees you receive the expected model performance with the robust data guarantees you require.
What This Means for Your Sensitive Data
Our commitment to ZDR translates into concrete protections for your valuable information:
- No Retention: Your prompts and AI outputs are never stored by model providers after processing.
- No Training Data: Your data is never used to train or improve third-party AI models.
- Never Your Sensitive Records: Customer Information – anything that identifies your organization, personnel, systems, assets, or intellectual property – is strictly prohibited from being used to train AI models, either by RiskForce or any of our partnered providers.
Important Note: It's worth noting that narrow exceptions may exist for some providers who, even with ZDR in place, flag illegal or egregious content. We always recommend reviewing vendor documentation for specific details.
Part of a Broader Data Protection Commitment
Zero Data Retention is not a standalone feature; it's an integral component of RiskForce's comprehensive data protection architecture:
- GovCloud Residency: Your data resides exclusively in GovCloud, a dedicated US environment meticulously aligned with FedRAMP, RMF, CMMC, and NIST 800-53 expectations.
- Your Data Stays Yours: We uphold the principle that your sensitive records remain your property and under your control.
- Transparent AI Labeling: All AI features are clearly labeled, ensuring transparency in their usage and data handling.
See It for Yourself
Are you ready to discover how RiskForce can bolster your compliance program without ever compromising your data integrity?
Start a free trial or request a demo today. We're eager to walk you through our robust security and data-handling practices in detail.