OpenAI Begins Phased Rollout of Private Safety Processing
The system reviews related API interactions for misuse while keeping prompts and responses outside retention, though safety records may remain for 30 days.

OpenAI began a phased rollout of Private Safety Processing to eligible API customers using Zero Data Retention on Sept. 22, extending automated safety checks across related interactions without exposing the underlying content to OpenAI personnel.
Private Safety Processing evaluates activity across multiple exchanges to identify potential misuse patterns that may not appear in a single request. When activity is detected, OpenAI receives only a narrowly defined signal about it, not the customer’s prompts, model responses or other underlying content.
Eligible customers using Zero Data Retention do not have their prompts or model responses retained after processing. Enterprise data is not used to train OpenAI models unless customers explicitly opt in.
The system distinguishes between customer content and safety records. Customers can store those records in infrastructure they control, where they may carry a 30-day time-to-live. The records are processed through hardware-attested computing designed to prevent human access to decrypted customer content.
Private Safety Processing can be configured for individual API projects with customer-controlled storage on Amazon Web Services, Microsoft Azure or Google Cloud. OpenAI is developing an additional storage option on its own infrastructure that would use encryption keys controlled by customers.
The approach is designed for enterprise and other API deployments that need safety monitoring across longer workflows while keeping sensitive information outside the provider’s reach. OpenAI previewed the system Aug. 19 before beginning the phased rollout.
Zero Data Retention does not cover every legal exception. Apparent child sexual abuse material may still be retained for manual review and reporting as required by law.


