A model can support a zero-data-retention arrangement while the agent feature around it stores sessions, files or memories. The purchase decision therefore belongs at the feature level. Start with the workflow you intend to run, identify every place it creates persistent state, and check each against the applicable provider arrangement.
This census records 31 feature and delivery-surface combinations across Anthropic, OpenAI, Google and AWS. It separates what provider documentation states from what remains unknown. It is a procurement reference, not a legal opinion or a certification that any deployment meets its obligations.
- 01A provider label is too broad.Messages, files, hosted sessions and tools can have different eligibility.
- 02State and abuse monitoring differ.Disabling response storage does not establish that every copy or log disappears.
- 03Deletion may require several operations.Session history, uploaded files and derived memories can have separate lifecycles.
- 04Unknown is a useful result.Ask the provider for a feature-specific answer instead of inferring it from a nearby service.
01 — Practical decisionRetention and eligibility by feature #
ZDR means zero data retention under the provider’s defined arrangement. BAA means a HIPAA business associate agreement; DPA means a data processing agreement, with Google’s CDPA label retained where documented. Eligibility does not establish that your organization has executed the required agreement.
Read the contract and deletion fields separately even where they share a column. “Conditional” requires the applicable account, model and feature settings. “Unknown” means the inspected source does not establish the field; it does not mean the provider has no agreement or deletion mechanism. Source letters resolve directly to provider pages.
| Provider documentation linked in every cell, read September 9, 2026. This sample is not an exhaustive product inventory or a vendor ranking. | |||
|---|---|---|---|
| Provider / feature | ZDR eligibility | Retention window | Contract and deletion path |
| --- | --- | --- | --- |
| Anthropic / Messages Source · Sep 9, 2026 | Conditional A · Sep 9, 2026 | No conversation-content storage by default; exceptions below A · Sep 9, 2026 | Contract: HIPAA eligible; DPA unknownA · Sep 9, 2026Delete: UnknownA · Sep 9, 2026 |
| Anthropic / Files Source · Sep 9, 2026 | No A · Sep 9, 2026 | Until deletion or configured expiry A · Sep 9, 2026 | Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Separate file deletionM · Sep 9, 2026 |
| Anthropic / Batch Source · Sep 9, 2026 | No A · Sep 9, 2026 | 29 days A · Sep 9, 2026 | Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Account representativeA · Sep 9, 2026 |
| Anthropic / Web search, no dynamic filtering Source · Sep 9, 2026 | Conditional A · Sep 9, 2026 | Response handling A · Sep 9, 2026 | Contract: HIPAA eligible; DPA unknownA · Sep 9, 2026Delete: UnknownA · Sep 9, 2026 |
| Anthropic / Web fetch, no dynamic filtering Source · Sep 9, 2026 | Conditional A · Sep 9, 2026 | Response handling; publisher policies separate A · Sep 9, 2026 | Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: UnknownA · Sep 9, 2026 |
| Anthropic / MCP connector Source · Sep 9, 2026 | No A · Sep 9, 2026 | Standard policy A · Sep 9, 2026 | Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Account representativeA · Sep 9, 2026 |
| Anthropic / MCP tunnels Source · Sep 9, 2026 | No A · Sep 9, 2026 | Unknown T · Sep 9, 2026 | Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Archive tunnel; remove local credentials; data erasure unknownT · Sep 9, 2026 |
| Anthropic / Managed Agents sessions Source · Sep 9, 2026 | No M · Sep 9, 2026 | Stored session history/state/output M · Sep 9, 2026 | Contract: BAA no; DPA unknownM · Sep 9, 2026Delete: Delete session; uploaded files separatelyM · Sep 9, 2026 |
| Anthropic / Scheduled deployments Source · Sep 9, 2026 | No: Managed Agents sub-feature A · Sep 9, 2026 | Session data persists; run-record TTL unknown A · Sep 9, 2026S · Sep 9, 2026 | Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Archive stops schedule; delete sessions/files separately; record erasure unknownS · Sep 9, 2026M · Sep 9, 2026 |
| OpenAI API / Chat Completions Source · Sep 9, 2026 | Conditional O · Sep 9, 2026 | No ordinary state; abuse logs up to 30 days by default; exceptions apply O · Sep 9, 2026 | Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: UnknownO · Sep 9, 2026 |
| OpenAI API / Responses foreground Source · Sep 9, 2026 | Conditional; store=false under ZDR O · Sep 9, 2026 | Default stored response ≥30 days O · Sep 9, 2026 | Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: Unknown in inspected pageO · Sep 9, 2026 |
| OpenAI API / Responses background Source · Sep 9, 2026 | Permitted from ZDR projects; temporary storage B · Sep 9, 2026 | Roughly 10 minutes with store=false B · Sep 9, 2026 | Contract: Responses BAA conditional; DPA unknownH · Sep 9, 2026Delete: Automatic after temporary polling periodB · Sep 9, 2026 |
| OpenAI API / Conversations Source · Sep 9, 2026 | No O · Sep 9, 2026 | Until deletion O · Sep 9, 2026 | Contract: UnknownH · Sep 9, 2026Delete: Deletion required; exact operation not checkedO · Sep 9, 2026 |
| OpenAI API / Files Source · Sep 9, 2026 | No O · Sep 9, 2026 | Until deletion/expiry O · Sep 9, 2026 | Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: API/dashboard; expires_afterO · Sep 9, 2026 |
| OpenAI API / Batch Source · Sep 9, 2026 | No O · Sep 9, 2026 | Until deletion O · Sep 9, 2026 | Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: Unknown in inspected pageO · Sep 9, 2026 |
| OpenAI API / Live web search Source · Sep 9, 2026 | Tool-specific classification unknown O · Sep 9, 2026 | Tool-specific window unknown O · Sep 9, 2026 | Contract: BAA no; DPA unknownO · Sep 9, 2026Delete: UnknownO · Sep 9, 2026 |
| OpenAI API / Cache-only web search Source · Sep 9, 2026 | ZDR setup required for BAA path O · Sep 9, 2026 | Tool-specific window unknown O · Sep 9, 2026 | Contract: BAA conditional; DPA unknownO · Sep 9, 2026Delete: UnknownO · Sep 9, 2026 |
| OpenAI API / Remote MCP Source · Sep 9, 2026 | Third-party boundary O · Sep 9, 2026 | MCP operator policy O · Sep 9, 2026 | Contract: Third-party agreement unknownO · Sep 9, 2026Delete: MCP operator; exact path unknownO · Sep 9, 2026 |
| OpenAI / Codex cloud Source · Sep 9, 2026 | Unknown C · Sep 9, 2026 | Unknown numeric window C · Sep 9, 2026 | Contract: BAA no; DPA unknownH · Sep 9, 2026Delete: UnknownC · Sep 9, 2026 |
| Google Cloud / Plain model inference Source · Sep 9, 2026 | Conditional configuration and model G · Sep 9, 2026 | Abuse/Advanced AI exceptions; inspect contract G · Sep 9, 2026 | Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: UnknownG · Sep 9, 2026 |
| Google Cloud / Search grounding Source · Sep 9, 2026 | No for this feature G · Sep 9, 2026 | Derived query/context logs ≤3 days G · Sep 9, 2026 | Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: Logging cannot be disabledG · Sep 9, 2026 |
| Google Cloud / Maps grounding Source · Sep 9, 2026 | No for this feature G · Sep 9, 2026 | Prompts/context/output 30 days G · Sep 9, 2026 | Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: Logging cannot be disabledG · Sep 9, 2026 |
| Google Cloud / Live session resumption Source · Sep 9, 2026 | Disable resumption for ZDR G · Sep 9, 2026 | Cached inputs/outputs ≤24 hours G · Sep 9, 2026 | Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: Exact deletion operation unknownG · Sep 9, 2026 |
| Google Cloud / Managed Agents preview Source · Sep 9, 2026 | Unknown; confidential-data use prohibited V · Sep 9, 2026 | Unknown numeric window V · Sep 9, 2026 | Contract: Pre-GA restrictions; BAA/DPA unknownV · Sep 9, 2026Delete: Project deletion documented; individual record erasure unknownV · Sep 9, 2026 |
| Gemini Developer API / Stored interactions (paid) Source · Sep 9, 2026 | Unknown program eligibility; stored state I · Sep 9, 2026 | 55 days; configurable 7/14/28/55 I · Sep 9, 2026 | Contract: BAA/DPA unknownI · Sep 9, 2026Delete: interactions.delete or AI Studio; expiryI · Sep 9, 2026 |
| Gemini Developer API / Stateless interactions Source · Sep 9, 2026 | Unknown program eligibility; store=false supported I · Sep 9, 2026 | Interaction storage disabled; other retention unknown I · Sep 9, 2026 | Contract: BAA/DPA unknownI · Sep 9, 2026Delete: No stored interaction; other deletion unknownI · Sep 9, 2026 |
| Gemini Developer API / Background interactions Source · Sep 9, 2026 | store=false incompatible I · Sep 9, 2026 | Stored interactions follow tier policy I · Sep 9, 2026 | Contract: BAA/DPA unknownI · Sep 9, 2026Delete: interactions.delete or AI Studio; expiryI · Sep 9, 2026 |
| Gemini Developer API / Files Source · Sep 9, 2026 | Unknown program eligibility; file storage required F · Sep 9, 2026 | 48 hours F · Sep 9, 2026 | Contract: BAA/DPA unknownF · Sep 9, 2026Delete: files.delete or automatic expiryF · Sep 9, 2026 |
| AWS AgentCore / Runtime sessions Source · Sep 9, 2026 | Unknown D · Sep 9, 2026 | Data window unknown; microVM lifetime is separate R · Sep 9, 2026 | Contract: Service HIPAA eligible; BAA/DPA terms unknownK · Sep 9, 2026Delete: Timeout terminates instance; session can resumeR · Sep 9, 2026 |
| AWS AgentCore / Short-term memory Source · Sep 9, 2026 | Unknown program eligibility; persistent events W · Sep 9, 2026 | Configured event retention ≤365 days W · Sep 9, 2026 | Contract: Service HIPAA eligible; BAA/DPA terms unknownK · Sep 9, 2026Delete: DeleteEvent; derived long-term memory survivesE · Sep 9, 2026 |
| AWS AgentCore / Long-term memory Source · Sep 9, 2026 | Unknown D · Sep 9, 2026 | Unknown numeric window W · Sep 9, 2026 | Contract: Service HIPAA eligible; BAA/DPA terms unknownK · Sep 9, 2026Delete: DeleteMemoryRecord separatelyL · Sep 9, 2026 |
02 — Practical decisionRead the conditions before using an eligible feature #
Anthropic’s eligibility documentation adds model-specific exceptions: Fable 5/5.1 and Mythos 5/5.1 require 30-day retention without express authorization. Search/fetch dynamic filtering is excluded from the eligible path. Flagged content may be retained up to two years, with legal exceptions. A feature-level yes cannot override those conditions.
OpenAI’s HIPAA guidance requires an executed BAA and Modified Retention for covered API use unless specified otherwise. Codex cloud is excluded. The API data-controls page separately conditions the cache-only web-search BAA path on supported non-preview tooling, disabled external web access and ZDR at organization and project level.
These details change how a procurement question should be phrased. Ask whether the exact model, endpoint, tools and settings are covered by the proposed agreement. A response about the general API may be accurate while leaving the intended hosted feature unanswered.
Our Astra–Fable comparison covers model selection. Use this feature census as a separate filter before running an evaluation with confidential material.
03 — Practical decisionWhat stateful agents cost the reviewer #
Persistent state can be useful: it lets work resume, keeps files available and avoids asking the user to repeat context. The review cost is identifying which resources exist, who can access them, how long they remain and which operation removes them. That work is part of choosing the runtime.
Claude Managed Agents documentation says the stateful service is outside current ZDR and HIPAA BAA eligibility. Session deletion and uploaded-file deletion are separate. The question for a buyer is whether that persistence fits an acceptable arrangement, not whether persistence is automatically disqualifying.
The current OpenAI background-mode guide permits requests from ZDR projects with store=false while retaining temporary polling data for roughly ten minutes. That is a specific documented exception to a literal expectation of no storage. Quote the behavior when assessing it rather than relying on an older blanket description of background mode.
Google’s managed-agent preview guide restricts confidential input and commercial/production use. General cloud data-governance statements do not remove those preview restrictions. Our Google managed-agent analysis provides product context; the current feature terms decide the allowed use.
04 — Practical decisionFollow deletion through the derived data #
Draw a simple resource list for a representative task: input request, session, uploaded file, tool result, memory, trace and export. Identify the owner and deletion operation for each. A request to delete the session should not be treated as proof that the other resources were removed.
AWS short-term event deletion documentation says deleting an event does not remove derived long-term memory. The latter has a separate DeleteMemoryRecord operation. Similarly, runtime lifecycle limits describe instance lifetime, not a universal data-retention promise. A stopped process and erased data are different outcomes.
Include destinations outside the runtime. A remote tool may receive information under its own policy, and an exported trace may remain in your observability system. The provider’s deletion operation cannot establish what your own retained export contains. Keep the data-flow map narrow enough that an engineer can verify it.
Our agent runtime and sandbox matrix helps identify execution boundaries. Add storage and deletion ownership to that runtime decision before calling the workflow ready for sensitive work.
05 — Practical decisionTurn unknown cells into precise provider questions #
An unknown cell should produce a question with a subject and a requested answer. For example: does this feature retain session content after an explicit delete request, and what documented window applies to primary copies and backups? Avoid asking whether the whole platform is compliant; that invites an answer too broad to settle the deployment.
Attach the model ID, region, feature name and enabled tools to the question. Ask which contract covers the service and whether an eligibility exception requires approval. Request a source or written commitment that can be retained with the deployment record.
For implementation, test the operations available to you using non-sensitive sample data: create the resource, find it, delete it and confirm the visible result. Such a test can establish that the control works in your application. It cannot independently establish deletion of provider backups or other internal copies; those require the provider’s documented commitment. Keep the census at the same URL and re-check it when the provider changes a feature or your workflow adds a new destination. A table read today is evidence for today’s decision, not a permanent certification. Our Claude Managed Agents update guide illustrates how runtime features can change the scope of an earlier review.
This is a documentation comparison, not a hands-on performance test.
- As-of date
- September 9, 2026. Published September 8 as an editorial backfill; collection happened the following day.
- Scope
- Purposive census of 31 feature/surface rows across four providers, researched from 18 provider documentation pages. Each cell includes its source and read date. Conditional is not default eligibility; unknown is not a negative finding. Contract columns record documentation statements, not a signed agreement or legal assessment.
- Refresh
- Review after provider policy or model changes. Unknown marks information the cited documentation does not state.
06 — Next stepWhat to do next #
Choose the complete data path, not the model label.
Filter the intended workflow by feature eligibility, retention behavior, contract and deletion path. Resolve consequential unknowns with the provider and preserve the answer with the deployment configuration. Stateful features can be a deliberate choice when their handling fits the requirement; a broad privacy label alone cannot establish that fit.
Our AI transformation services help teams define a useful pilot, evaluate its results and turn the findings into an implementation decision.