OpenAI previews Private Safety Processing for Zero Data Retention customers

OpenAI is previewing a new feature called Private Safety Processing, built on top of its existing Zero Data Retention (ZDR) API service for eligible customers. Under ZDR, OpenAI does not retain a customer's prompts or model responses once a request has been processed, that content is not available to OpenAI personnel for review, and enterprise customer data is not used to train OpenAI's models unless the customer explicitly opts in. Private Safety Processing extends this setup rather than replacing it.
The feature responds to a specific gap OpenAI describes: as models take on longer and more complex tasks, some of the most serious safety risks are not visible in any single interaction and only become clear once several related interactions are viewed together. OpenAI points to examples such as an attacker repeatedly probing safeguards, coordinating abuse across multiple accounts, disguising a threat as routine research, or an agentic system that keeps acting after being told to stop. Existing ZDR-compatible safety systems, per OpenAI, evaluate each interaction on its own and can miss that kind of pattern. OpenAI also says some recent frontier-model deployments have addressed this gap by requiring customers to let the provider retain sensitive content for safety monitoring, a condition it says conflicts with many organizations' own security obligations; Private Safety Processing is presented as a way for OpenAI to keep offering full ZDR while still catching risks that only show up across multiple interactions.
By OpenAI's description, automated systems analyze related interactions for patterns of misuse without giving OpenAI personnel access to the underlying prompts or responses. This holds whether the content sits on infrastructure the customer already controls, the standard ZDR setup, or, in an option OpenAI says it is still developing rather than offering today, on OpenAI's own infrastructure while encrypted with keys that only the customer holds; OpenAI personnel do not have a copy of that key and so cannot read the content. When the automated system flags a risk, OpenAI says it receives only a narrowly defined signal describing the type of activity involved, similar to what its existing safety systems already produce, and uses that signal to decide whether enforcement is needed; personnel still do not get access to the flagged content itself. Customers can investigate alerts and enforcement decisions using their own internal systems, and if they want to appeal a decision, explain legitimate activity, or support an investigation into confirmed abuse, they can choose to share relevant information with OpenAI themselves.
Private Safety Processing is currently being tested with early customers, one of which, Glean, is quoted in the announcement crediting OpenAI's no-training commitment and ZDR with giving it confidence to build on the platform; the quote is presented as a company statement rather than attributed to a named individual. OpenAI says the organizations it works with handle some of the most sensitive information in their sectors, including financial records, health data, confidential business plans and proprietary research, and that feedback from customers across industries, regions and company sizes is shaping the design. Even full ZDR keeps one stated exception: like other frontier-model providers, OpenAI is legally required to report apparent child sexual abuse material, so images flagged as potential CSAM continue to be retained for manual review and reporting even in ZDR deployments, as they are today. OpenAI says it plans to start a broader rollout of Private Safety Processing, along with a technical white paper, in September, and will keep working with customers on technical and operational details before then.
Key facts
- OpenAI is previewing Private Safety Processing, a new safety layer for its Zero Data Retention (ZDR) API service, designed to spot risk patterns across multiple related interactions without giving OpenAI staff access to the underlying content.
- Under ZDR, OpenAI does not retain a customer's prompts or responses after a request is processed, and enterprise data is not used for training unless the customer opts in; the one stated exception is images flagged as potential CSAM, which OpenAI is legally required to retain for reporting.
- Content stays on the customer's own infrastructure under standard ZDR, or, in an option OpenAI is still developing, on OpenAI's infrastructure encrypted with keys that only the customer holds and OpenAI personnel cannot access.
- When automated systems flag a risk, OpenAI says it receives only a narrowly defined signal about the type of activity, not the underlying content; customers can investigate using their own systems and may choose to share information with OpenAI to appeal a decision.
- Private Safety Processing is currently being tested with early customers, including Glean, which is quoted endorsing OpenAI's ZDR and no-training commitments; OpenAI plans to begin a broader rollout and publish a technical white paper in September.
Why it matters
OpenAI says the most serious AI safety risks are not always visible in a single interaction: harmful intent often only becomes clear once several interactions are viewed together, such as an attacker repeatedly probing safeguards, coordinating abuse across multiple accounts, disguising a threat as routine research, or an agentic system that keeps acting after being told to stop. Existing ZDR-compatible safety tools, by OpenAI's own account, only evaluate each interaction on its own, so this kind of pattern can slip through. OpenAI also says some recent frontier-model deployments have handled this by requiring customers to let the provider retain sensitive content for safety monitoring, a condition that it says conflicts with many organizations' own security obligations. Private Safety Processing is OpenAI's attempt to close that gap without giving up ZDR's no-retention promise, so customers no longer have to choose between full privacy and cross-interaction safety coverage.
Who it affects
Eligible API customers already using Zero Data Retention, particularly enterprises that handle sensitive material such as financial records, health data, confidential business plans and proprietary research, since OpenAI cites exactly those categories when describing the organizations it works with. The feature is only in preview and being tested with early customers, one of which is Glean, quoted endorsing OpenAI's data-control commitments; OpenAI says input from customers across industries, regions and company sizes is shaping the design. Customers outside that early group cannot use it yet, since general availability has not started.
How to use it
There is no general access yet: Private Safety Processing is in preview and running only with early customers, and OpenAI has not published pricing, eligibility criteria or a contract tier for it. Content protection works one of two ways. Under standard ZDR it stays on infrastructure the customer already controls. In an option OpenAI says it is still developing rather than offering today, it can instead sit on OpenAI's own infrastructure encrypted with keys the customer holds, which OpenAI staff cannot access. If the automated system flags a risk, OpenAI staff still are not shown the underlying content, only a narrowly defined signal describing the type of activity; a customer that wants to contest a flag, explain legitimate activity, or assist an abuse investigation can choose to share relevant information with OpenAI itself. OpenAI says a broader rollout, together with a technical white paper explaining the mechanism in more depth, is planned to start in September.
How solid is it
This is a preview announcement, not a shipped, generally available feature: OpenAI describes Private Safety Processing as currently being tested with early customers, and frames the September date as a plan to start rolling it out rather than a launch that has already happened. The technical description in the announcement stays at the level of intent: OpenAI says its systems detect patterns without personnel gaining access to retained customer content, but does not explain the underlying mechanism; that detail is promised for a later technical white paper. The one customer testimonial included, from Glean, is a quote OpenAI itself selected for the announcement, not independent verification. No number of early customers, no specific frontier models covered, and no named recent deployments that required retention for safety monitoring appear in the text, so several of the surrounding claims cannot be checked against specifics.
Risks and caveats
Even under Zero Data Retention, OpenAI's own footnote states one exception: images flagged for potential CSAM are still retained for manual review and legally required reporting, as they are today, so zero retention is not absolute. The privacy design rests on OpenAI's own account of its access controls, such as staff not holding a copy of customer-controlled encryption keys, which the announcement does not independently substantiate. Automated pattern detection across interactions still means OpenAI's systems, not the customer, make the first call on what looks like misuse, and the announcement gives no detail on how often that signal might be wrong or what recourse looks like beyond a customer voluntarily sharing information to appeal. The option to store content on OpenAI's own infrastructure while encrypting it with customer-held keys is explicitly still in development, not available today, so customers who want ZDR now still need infrastructure of their own to host the content.
“OpenAI’s no-training commitment and ZDR give Glean confidence to build with OpenAI. As models become more capable, OpenAI shows safety can advance without compromising the privacy and control that sustain enterprise trust.”
— Glean, in a customer testimonial quoted by OpenAI