Methodology
An opinion on published documentation. We do not run a penetration test, and we cannot prove absence from outside.
Public assessments cite their sources and state what was reviewed. Published documentation, an applicable agreement, and deployment evidence answer different questions. We make those distinctions explicit.
We score published promises. We cite the sentence. We do not invent scores.
Four promises ZDR conflates
The market uses “zero data retention” for four different promises:
- No-training
- No-retention
- No-logging
- No-human-review
A vendor can keep three and still fail the fourth. The score records residual third-party retention of content, not the marketing label.
What this is
An opinion on published documentation: API references, DPAs, trust-center pages, and the sentences linked on each dossier. Last-verified is a clerk mark, not a continuous scan.
Under provider custody, PRC-origin models are ordered last because third-party retention cannot be independently verified. Under customer custody, order is the score.
What this is not
We cannot prove absence from outside. A 0.0 requires architectural verification that no external party receives plaintext. No seed endpoint holds that score.
Corrections
Material error: 48 hours from a sourced correction against the cited sentence.
Notation: ZDR 1.0 (s,f,r) · A is score, flags, evidence grade, in that order. Lower is better.
Speak to a ZDR expert about applying this method to your agreements.