Scale

Distance from zero. Lower is better. Write ZDR 1.0 (s,f,r) · A as score, flags, evidence.

The ZDR Scale

ZDR 4.0
Open intake. Trains on content by default, or retention undefined/indefinite.
ZDR 3.0
No-training. No training, but retention unbounded or unspecified.
ZDR 2.0
Bounded retention. Content retained a defined window (<=90d) for abuse monitoring, possibly human-reviewed, then deleted.
ZDR 1.0
Contractual ZDR. Paper ZDR: no content retention by agreement, with typed carve-outs in force.
ZDR 0.5
Architectural ZDR. Nothing durably written by provider; stateful features blocked/rejected; still third-party plaintext processing.
ZDR 0.0
Sovereign. No external party ever receives plaintext. The badge tier is earned via architectural verification, never purchased. No seed endpoint holds this score. That absence is the point of the badge.

Exception flags

s
safety-flag retention beyond base window
f
stateful-feature carve-outs (files, batch, threads, caching, grounding)
h
human review possible
r
revocable: provider reserves unilateral downgrade
x
subprocessor exposure

Evidence grades

V
cryptographically verified (TEE attestation, transparency logs)
A
contractual (DPA/agreement-backed)
B
published documentation
C
marketing or support-article claims

Universal floor

Legal hold, CSAM, lawful process, and operational metadata apply at every score above 0.0. Quoted floor: legal process, CSAM statutory duties, operational metadata apply at every score above 0.0.

Procurement language

No AI subprocessor worse than ZDR 1.0, evidence grade B or above.

No seed endpoint is 0.0. Sovereign is earned by architectural verification that no external party receives plaintext. It is not a pricing tier and it is not for sale.