FARADEX / ARTICLES / ZERO DATA RETENTION
Zero Data Retention Isn't the Same at Every AI Vendor
What ZDR covers with Anthropic, on Amazon Bedrock, and in the Claude apps, plus four questions to ask any AI vendor, and how Faradex answers them.
"Zero data retention" sounds like one promise. It is not used the same way everywhere. At one provider the same three words describe a contract arrangement, and at another an account setting. They do not apply at all to Anthropic's Claude apps.
For firms handling client work, the difference is not academic: AI conversations that exist can be subpoenaed and used as evidence. Here is what ZDR covers in each case, based on the providers' own documentation as of [date].
With Anthropic, ZDR is an arrangement you request
On Anthropic's own API, zero data retention is not a default. An organization requests it through Anthropic's sales team, and Anthropic enables it one organization at a time.[1]
Where it applies, it covers the Messages and Token Counting endpoints, for eligible features only, plus Claude Code used with commercial API keys. Claude Code on Claude Enterprise has its own ZDR offering, which is enabled separately.[1][2]
Even under ZDR, Anthropic keeps safety-classifier results and may keep data tied to Usage Policy violations.[2][3]
Claude's apps, and some API products, are not covered
ZDR does not apply to any of the following:[1]
- the Claude.ai web, desktop, or mobile apps
- the Claude Team and Enterprise chat interfaces
- the Claude Console and its playground
- Claude Managed Agents, which is an API product
In Claude Enterprise, chats are kept indefinitely unless an admin sets a custom retention period, and the minimum period is 30 days.[4] When a user deletes a chat, it leaves their history immediately and is deleted from Anthropic's backend within 30 days.[5] Claude Managed Agents sessions persist until you delete them.[1][6]
"No training" is a different promise from "no retention"
Anthropic's commercial products (Team, Enterprise, and the API) do not use your data for training without your permission.[1] That promise is about training. It says nothing about storage.
In the Team and Enterprise apps, chats are kept until they are deleted.[4][5]
On Amazon Bedrock, the arrangement is different
When you use Claude through Amazon Bedrock, AWS runs the model and processes the data, not Anthropic. AWS documents that model providers "don't have access to Amazon Bedrock logs or to customer prompts and completions."[7] AWS also states that Bedrock does not share content with model providers today.[8]
AWS lets each customer choose a data-retention mode for each Region. In its zero-data-retention mode, AWS documents that "no request or response data is written to durable storage by AWS or shared with the model provider."[8] Faradex runs that mode in every Region it uses.
Who can see your data, and whether it is kept, are separate questions
AWS states that "Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output."[9] Zero operator access limits who can see your data. It does not decide whether that data is stored. AWS lists zero data retention as a separate model.
A SOC 2 report is not a retention promise
A SOC 2 report is an independent auditor's opinion on an organization's controls. The auditor measures those controls against the AICPA's trust services criteria, and only within the scope the organization defines.[10]
- A Type 1 report looks at the design of those controls on a single date.
- A Type 2 report tests whether they operated effectively over a period.
Neither report, by itself, guarantees any particular retention policy.
Four questions to ask any AI vendor, including us
These are the questions we recommend asking before you trust any AI vendor's retention claim. Here is how Faradex answers each one.
1. Who processes your data: the model provider, a cloud provider, or both?
Faradex runs Anthropic's Claude models through Amazon Bedrock, inside AWS. AWS processes inference, and AWS documents that model providers, Anthropic included, have no access to Bedrock prompts or completions.[7] Nothing you do in Faradex is used to train any model, by Faradex or by the model provider.
Your swarm of agents works alongside your team inside your own dedicated instance, which no other customer shares. Every Faradex service runs in the USA, and your data never leaves the country.
2. Is no-retention a default, a setting you control, or a contract term you have to request?
At the model layer, it is a setting Faradex controls, not a contract term we had to request. Faradex's AWS account runs Amazon Bedrock in zero-data-retention mode in every Region it uses. AWS describes that mode this way: "No request or response data is written to durable storage by AWS or shared with the model provider."[8] So AWS does not store your prompts or responses, and model providers have no access to them.[7]
Inside Faradex, your uploaded files are processed in memory only and are never written to disk. Your conversations, and the database your instance keeps while you work, live only in memory too. Nothing is written to disk. This is a hardware-level architectural constraint, not a retention policy. Nothing is backed up, and Faradex cannot access your instance. When you reset or delete your instance, it is gone, and no copy exists anywhere.
Apart from the AI requests themselves, which Bedrock processes under zero retention, no request or response data ever leaves your instance. Audit logs carry no content, only metadata (who did what, and when). AWS tracks AI usage for billing only.
3. Which models, features, and apps are excluded?
Faradex connects your agents to Claude only through Bedrock, never through the Claude apps or Anthropic's own API, so the app and API exclusions above do not apply. AWS documents that in zero-data-retention mode it blocks any request to a model that requires retention.[8] Faradex's account runs in zero-data-retention mode in every Region it uses, so those models are never used for your work.
4. If the vendor cites SOC 2: what type, and what scope?
Faradex has completed a SOC 2 Type 1 examination, performed by Sensiba. It covers our Secure III and Secure IV plans. Our SOC 2 Type 2 observation period is underway, and our SOC 2 report is available on request.
Faradex doesn't ask you to rely on one promise, because we believe private AI is a human right. AWS does not store your prompts or responses, the model provider has no access to them, and Faradex's own architecture retains nothing it could produce.
See how the architecture works: Security
Last reviewed: [date]. Sources retrieved October 3, 2026. Provider terms change, so we re-check this page every quarter and whenever a new Claude model ships on Bedrock.
Sources
- Anthropic, "API and data retention," Claude Platform Docs. https://platform.claude.com/docs/en/manage-claude/api-and-data-retention
- Anthropic, "Zero data retention," Claude Code Docs. https://code.claude.com/docs/en/zero-data-retention
- Anthropic Privacy Center, "I have a zero data retention agreement with Anthropic…" https://privacy.claude.com/en/articles/8956058
- Anthropic Privacy Center, "Configure custom data retention controls for Enterprise plans." https://privacy.claude.com/en/articles/10440198-configure-custom-data-retention-controls-for-enterprise-plans
- Anthropic Privacy Center, "How long do you store my organization's data?" https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data
- Anthropic, "Claude Managed Agents overview," Claude Platform Docs. https://platform.claude.com/docs/en/managed-agents/overview
- Amazon Web Services, "Data protection," Amazon Bedrock User Guide. https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html
- Amazon Web Services, "Data retention," Amazon Bedrock User Guide. https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html
- Amazon Web Services, "Amazon Bedrock abuse detection," Amazon Bedrock User Guide. https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.html
- AICPA, "SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy." https://www.aicpa-cima.com/cpe-learning/publication/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy