Searchable endpoint register
Provider registry
Find the service you use. Check what its published terms cover, the exceptions, and the evidence behind our assessment. For the viral scoreboard view, see ZDR Rankings.
Registry table
Need help applying a provider’s terms to your deployment? Speak to a ZDR expert.
| Provider and service | Retention conditions | ZDR score ▲ | Evidence | Sources reviewed |
|---|---|---|---|---|
|
|
Zero operator access; nothing durably written; providers can't see traffic. OpenAI frontier models: flagged traffic <=30d; covered Anthropic models require provider_data_share. | ZDR 0.5 | Contractual agreement reviewedA | 2026-08-24 (registry) |
|
|
Claims no retention of prompts/outputs; support-article grade, no formal program. Absence of a documented safety exception is itself a red flag under the framework. | ZDR 0.5 | Marketing or support claimsC | 2026-08-24 (registry) |
|
|
ZDR by default, volatile memory only. Responses API defaults store=true -> 30d; proprietary Fireworks models may log. | ZDR 0.5f | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
Possible <=30d reliability/abuse logs; toggle disables even those. Customer assumes abuse-compliance responsibility; US-region storage for anything retained. | ZDR 0.5 | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
Routes only to endpoints OpenRouter marks as zero-retention. OpenRouter itself does not store prompts unless you opt in. Still third-party plaintext. Implicit prompt cache is not treated as retention; plugins and web search keep their own policies; ZDR is claimed by upstream, not verified here. | ZDR 0.5f,x | Public documentation reviewedB | 2026-08-25 |
|
|
Published ZDR for the Chat Completions API: no prompt or response retain, no training, billing metadata only. Covers the API only, not the consumer search product. Compute hosted on AWS in North America. | ZDR 0.5 | Public documentation reviewedB | 2026-08-25 |
|
|
No storage by default ('supports ZDR'); training/storage opt-in. Passthrough models forward to upstream policies; no serverless region selection. | ZDR 0.5x | Marketing or support claimsC | 2026-08-24 (registry) |
|
|
Default 30d encrypted storage; ZDR self-serve, confirmed via x-zero-data-retention header. Disables stateful features wholesale; audit event logs continue. | ZDR 0.5r | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
No content retention. Safety carve-outs survive ZDR; stateful features step outside ZDR and are NOT blocked; classifier results retained. | ZDR 1.0s,f,r | Contractual agreement reviewedA | 2026-08-24 (registry) |
|
|
Approved enterprise ZDR: Cohere does not log prompts or generations. Usage metadata still collected. Abuse monitoring is weaker. Not self-serve. Usage data still received. Private and partner deployments are a different isolation path. | ZDR 1.0s,r | Public documentation reviewedB | 2026-08-25 |
|
|
Flag-triggered abuse logging only, <=90d, in-region; 24h caching on by default. Advanced AI Safety Addendum: ZDR 'may not be possible' on some advanced models; grounding logs 3d non-disablable. | ZDR 1.0s,f,r | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
No OpenAI access; abuse monitoring w/ flagged-sample human review (automated LLM review default); store duration removed from canonical page. Automated review continues under MAM; severe abuse can force monitoring back on; stateful features persist; stricter criteria for advanced models. | ZDR 1.0s,f,h,r | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
Default 30d rolling abuse logs; EU storage. Stateless endpoints only; agents/batch/files excluded; Labs models train regardless. | ZDR 1.0f | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
No content retention; store forced false. CSAM image scan retains flagged inputs; Eyes Off / Safety Retention allow per-model downgrade with notice; stateful endpoints ineligible; videos endpoint blocked. | ZDR 1.0s,f,r | Contractual agreement reviewedA | 2026-08-24 (registry) |
|
|
30d auto-delete; no training without permission. Flagged content <=2y; classifier scores <=7y. | ZDR 2.0s | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
Mandatory 30d retention incl. ZDR orgs; on Bedrock, sharing with Anthropic required. Flagged-content human-review path; defining example of flag r. | ZDR 2.0s,h | Contractual agreement reviewedA | 2026-08-24 (registry) |
|
|
Abuse logs 55d, storable in any country; no product-improvement use. Search grounding stores 30d non-disablable; Interactions API store defaults true; Live API caches 24h. | ZDR 2.0f,h | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
Possible <=30d reliability and abuse logs unless the ZDR toggle is on. US-region storage for anything retained. | ZDR 2.0 | Public documentation reviewedB | 2026-08-25 |
|
|
30d rolling abuse logs; EU storage; no training on API traffic in the published ZDR docs. Agents, batch, and files sit outside the ZDR path; Labs models train regardless. | ZDR 2.0f | Public documentation reviewedB | 2026-08-25 |
|
|
Abuse logs incl. content <=30d; Responses API stores state 30d (store defaults true); no training. Stateful endpoints retained until deleted; assistants objects indefinitely. | ZDR 2.0f,h | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
API prediction inputs, outputs, files, and logs are automatically removed after one hour by default. Web-interface predictions are kept indefinitely. Fine-tunes are a different store. | ZDR 2.0f | Public documentation reviewedB | 2026-08-25 |
|
|
30d encrypted storage of content unless the ZDR toggle is on. Audit event logs continue under both postures. | ZDR 2.0 | Public documentation reviewedB | 2026-08-25 |
|
|
No training and no service-improvement use of Customer Content without consent. Docs do not state a prompt-log deletion window. R2, KV, Durable Objects, and Vectorize persist content by design. Inference-payload logging is unspecified. | ZDR 3.0f | Public documentation reviewedB | 2026-08-25 |
|
|
Hugging Face does not store request bodies or responses when routing and does not store user data for training. Default routing still forwards plaintext to upstream providers. Debug logs up to 30 days without user data. Dedicated Inference Endpoints are a different product. Score is the hop, not each partner. | ZDR 3.0x | Public documentation reviewedB | 2026-08-25 |
|
|
No-training and encryption claims in launch material; no published retention schedule. | ZDR 3.0 | Marketing or support claimsC | 2026-08-24 (registry) |
|
|
OpenRouter itself does not store prompts unless you opt in. Default routing can land on providers that retain or train. If a provider policy is unclear, OpenRouter assumes retain-and-train. Plugins and tools are outside ZDR enforcement; anonymous prompt categorization is sampled. | ZDR 3.0x | Public documentation reviewedB | 2026-08-25 |
|
|
SaaS logs prompts and generations for 30 days. Training use is an opt-out dashboard toggle, so prompts train unless turned off. Enterprise Data Commitments do not apply to trial keys. Flagged misuse may be retained and reviewed. Private deployments receive no prompts. | ZDR 4.0s,h,r,x | Public documentation reviewedB | 2026-08-25 |
|
|
Trial ToS: User Content and Generated Content are collected to improve NVIDIA products and services, including AI models. Self-hosted NIM is a different endpoint. Fine-tune uploads may be stored 30 days. Abuse and fraud logging uses subprocessors. | ZDR 4.0s,x | Contractual agreement reviewedA | 2026-08-25 |
|
|
API DPA: inputs and outputs are processed in real time and not saved on servers. Additional Terms: End User Content is not used to develop or improve services unless the customer agrees. Consumer chat is a different posture. Abuse and legal uses remain. Mainland bigmodel.cn is not this row. Processing stated as Singapore. | ZDR 1.0s | Contractual agreement reviewedA | 2026-08-25 |
|
|
Privacy notice: will never use your data for model training. FAQ: Model Studio stores data generated from model and application calls. No published deletion window for standard chat traffic. Responses / batch / task APIs store state (batch results 30d; async tasks 24h); region-selectable storage including Beijing. | ZDR 3.0f | Public documentation reviewedB | 2026-08-25 |
|
|
Trains on inputs by default (email opt-out); retention up to life of account; PRC storage; group sharing. US hosts serving DeepSeek weights are different endpoints with different scores. | ZDR 4.0 | Public documentation reviewedB | 2026-08-24 (registry) |
|
|
Terms authorize use of input and generated content to develop and improve services. Privacy gives no fixed deletion window. A line about not using personal data to profile consumers is not a no-training promise. No published ZDR. | ZDR 4.0s | Public documentation reviewedB | 2026-08-25 |
|
|
OpenPlatform privacy: user content is used to train and refine models, and account, input, and payment information are retained while the account is active. API help page separately claims API data is not used for training. Storage stated as Singapore. Help Center contradicts the privacy policy on training. Files persist until deleted. Content safety review exists. Mainland moonshot.cn not scored separately. | ZDR 4.0f | Public documentation reviewedB | 2026-08-25 |
-
AWSBedrock, data_retention_mode:none, non-covered models
Zero operator access; nothing durably written; providers can't see traffic. OpenAI frontier models: flagged traffic <=30d; covered Anthropic models require provider_data_share.
-
Cerebrasinference API
Claims no retention of prompts/outputs; support-article grade, no formal program. Absence of a documented safety exception is itself a red flag under the framework.
-
Fireworks AIopen models
ZDR by default, volatile memory only. Responses API defaults store=true -> 30d; proprietary Fireworks models may log.
-
GroqZDR toggled
Possible <=30d reliability/abuse logs; toggle disables even those. Customer assumes abuse-compliance responsibility; US-region storage for anything retained.
-
OpenRouterhop, zdr enforced
Routes only to endpoints OpenRouter marks as zero-retention. OpenRouter itself does not store prompts unless you opt in. Still third-party plaintext. Implicit prompt cache is not treated as retention; plugins and web search keep their own policies; ZDR is claimed by upstream, not verified here.
-
PerplexityChat Completions / Sonar API
Published ZDR for the Chat Completions API: no prompt or response retain, no training, billing metadata only. Covers the API only, not the consumer search product. Compute hosted on AWS in North America.
-
Together AIserverless default
No storage by default ('supports ZDR'); training/storage opt-in. Passthrough models forward to upstream policies; no serverless region selection.
-
xAIZDR toggled
Default 30d encrypted storage; ZDR self-serve, confirmed via x-zero-data-retention header. Disables stateful features wholesale; audit event logs continue.
-
AnthropicZDR org, non-covered models
No content retention. Safety carve-outs survive ZDR; stateful features step outside ZDR and are NOT blocked; classifier results retained.
-
CohereSaaS API, ZDR approved
Approved enterprise ZDR: Cohere does not log prompts or generations. Usage metadata still collected. Abuse monitoring is weaker. Not self-serve. Usage data still received. Private and partner deployments are a different isolation path.
-
GoogleVertex / Gemini Enterprise Agent Platform
Flag-triggered abuse logging only, <=90d, in-region; 24h caching on by default. Advanced AI Safety Addendum: ZDR 'may not be possible' on some advanced models; grounding logs 3d non-disablable.
-
MicrosoftAzure OpenAI / Foundry, modified abuse monitoring
No OpenAI access; abuse monitoring w/ flagged-sample human review (automated LLM review default); store duration removed from canonical page. Automated review continues under MAM; severe abuse can force monitoring back on; stateful features persist; stricter criteria for advanced models.
-
MistralZDR approved
Default 30d rolling abuse logs; EU storage. Stateless endpoints only; agents/batch/files excluded; Labs models train regardless.
-
OpenAIfirst-party API, ZDR approved
No content retention; store forced false. CSAM image scan retains flagged inputs; Eyes Off / Safety Retention allow per-model downgrade with notice; stateful endpoints ineligible; videos endpoint blocked.
-
Anthropicfirst-party API, default
30d auto-delete; no training without permission. Flagged content <=2y; classifier scores <=7y.
-
AnthropicFable 5 / Mythos 5, all platforms
Mandatory 30d retention incl. ZDR orgs; on Bedrock, sharing with Anthropic required. Flagged-content human-review path; defining example of flag r.
-
GoogleGemini Developer API, paid tier
Abuse logs 55d, storable in any country; no product-improvement use. Search grounding stores 30d non-disablable; Interactions API store defaults true; Live API caches 24h.
-
Groqfirst-party API, default
Possible <=30d reliability and abuse logs unless the ZDR toggle is on. US-region storage for anything retained.
-
Mistralfirst-party API, default
30d rolling abuse logs; EU storage; no training on API traffic in the published ZDR docs. Agents, batch, and files sit outside the ZDR path; Labs models train regardless.
-
OpenAIfirst-party API, default
Abuse logs incl. content <=30d; Responses API stores state 30d (store defaults true); no training. Stateful endpoints retained until deleted; assistants objects indefinitely.
-
ReplicatePredictions API, not the web UI
API prediction inputs, outputs, files, and logs are automatically removed after one hour by default. Web-interface predictions are kept indefinitely. Fine-tunes are a different store.
-
xAIfirst-party API, default
30d encrypted storage of content unless the ZDR toggle is on. Audit event logs continue under both postures.
-
CloudflareWorkers AI API
No training and no service-improvement use of Customer Content without consent. Docs do not state a prompt-log deletion window. R2, KV, Durable Objects, and Vectorize persist content by design. Inference-payload logging is unspecified.
-
Hugging FaceInference Providers hop
Hugging Face does not store request bodies or responses when routing and does not store user data for training. Default routing still forwards plaintext to upstream providers. Debug logs up to 30 days without user data. Dedicated Inference Endpoints are a different product. Score is the hop, not each partner.
-
MetaMeta Model API
No-training and encryption claims in launch material; no published retention schedule.
-
OpenRouterhop, default routing
OpenRouter itself does not store prompts unless you opt in. Default routing can land on providers that retain or train. If a provider policy is unclear, OpenRouter assumes retain-and-train. Plugins and tools are outside ZDR enforcement; anonymous prompt categorization is sampled.
-
CohereSaaS Platform API, default
SaaS logs prompts and generations for 30 days. Training use is an opt-out dashboard toggle, so prompts train unless turned off. Enterprise Data Commitments do not apply to trial keys. Flagged misuse may be retained and reviewed. Private deployments receive no prompts.
-
NVIDIAAPI Catalog / hosted NIM trial
Trial ToS: User Content and Generated Content are collected to improve NVIDIA products and services, including AI models. Self-hosted NIM is a different endpoint. Fine-tune uploads may be stored 30 days. Abuse and fraud logging uses subprocessors.
-
Z.AIinternational Model API (api.z.ai), not mainland BigModel
API DPA: inputs and outputs are processed in real time and not saved on servers. Additional Terms: End User Content is not used to develop or improve services unless the customer agrees. Consumer chat is a different posture. Abuse and legal uses remain. Mainland bigmodel.cn is not this row. Processing stated as Singapore.
-
AlibabaQwen / Model Studio API
Privacy notice: will never use your data for model training. FAQ: Model Studio stores data generated from model and application calls. No published deletion window for standard chat traffic. Responses / batch / task APIs store state (batch results 30d; async tasks 24h); region-selectable storage including Beijing.
-
DeepSeekfirst-party API
Trains on inputs by default (email opt-out); retention up to life of account; PRC storage; group sharing. US hosts serving DeepSeek weights are different endpoints with different scores.
-
MiniMaxOpen Platform first-party API
Terms authorize use of input and generated content to develop and improve services. Privacy gives no fixed deletion window. A line about not using personal data to profile consumers is not a no-training promise. No published ZDR.
-
MoonshotKimi API, first-party
OpenPlatform privacy: user content is used to train and refine models, and account, input, and payment information are retained while the account is active. API help page separately claims API data is not used for training. Storage stated as Singapore. Help Center contradicts the privacy policy on training. Files persist until deleted. Content safety review exists. Mainland moonshot.cn not scored separately.
No matching services. Try another provider name or clear the filters.
Can’t find the service you’re evaluating? Ask a ZDR expert.