OpenAI’s September 29 Private Intelligence announcement distinguishes available Zero Data Retention with Private Safety Processing from a separate Private Inference preview planned for later in the fall. ZDR with PSP enables automated safety review under a different storage and access model; it does not mean no records exist anywhere.
Customer-controlled storage is part of the design
The PSP documentation describes encrypted records in customer-controlled cloud storage and a hardware-attested review runtime designed to exclude human access. It requires customers to retain encrypted records for at least 30 days and maintain the needed storage and key permissions.
For a security review, draw the data path before applying labels such as “zero retention” or “private.” Identify what is retained, who controls its storage, which workload can decrypt it, and what information leaves the protected runtime. These questions are more useful than interpreting a product name as an absolute confidentiality guarantee.
Project configuration is an operational dependency
The guide makes PSP a project-level policy and describes setup for supported cloud storage. A configuration error can therefore affect availability as well as privacy controls. Choose a clear owner for storage lifecycle rules, regional placement, and key authorization.
Test how the system behaves when required storage or key access disappears. Monitoring should distinguish a provider model error from a failed policy dependency. Preserve enough non-sensitive metadata to diagnose the problem, while keeping request content and credentials out of ordinary logs.
Do not confuse safety processing with private inference
The DevDay recap describes Private Inference as a future preview. PSP’s safety-review architecture is not evidence that all model inference already runs under those forthcoming controls.
Procurement and architecture reviews should name the specific capability covered by a claim. Ask whether a contract concerns inference processing, abuse review, application storage, or all three. An application’s own tracing, analytics, and support systems can retain sensitive information even when the model provider applies a stronger control.
When the design is worth evaluating
PSP matters for organizations that need frontier capabilities and want a more controlled safety-review data path. It also adds customer responsibilities that need staffing and testing. Compare the documented architecture with your threat model, residency requirements, and ability to operate the storage dependency.
Adoption should follow a review of the technical and contractual scope. Confidential computing narrows particular access paths; it does not replace application authorization, careful logging, or an incident-response process.