Start by separating three questions: who receives the text, whether the host stores the prompt, and whether the host can train on it. For confidential files, choose a path with a documented no-storage or no-training default, then confirm file upload limits and model routing. If the document must never leave your trust boundary, prefer a private model or enclave path over a general router.
What matters most when confidentiality is the deciding factor?
The selection criterion is not which model is strongest, but which provider’s operating model best matches your data-handling constraints. For confidential documents, the practical question is whether the service can receive text, retain it, or reuse it in ways that expand exposure. That means you should evaluate transport, storage, retention, and training behavior as separate controls, not as one generic “privacy” claim.
Most teams should treat “no storage” and “no training” as different promises. A provider can avoid training on your content and still keep prompts for a period of time for abuse detection, logging, or operational troubleshooting. That distinction is material when the document contains regulated, contractual, legal, or strategic information.
How do storage, training, and routing change the risk picture?
Storage risk is about who can later access the text, how long it persists, and whether it can be copied into logs, caches, support workflows, or analytics systems. Training risk is about whether your content can influence future model behavior or be retained in a way that is not limited to your session. Routing risk is about whether your prompt is sent to a general broker, a third-party model, or multiple backends without clear disclosure.
If the host can route requests across models, also confirm whether every route inherits the same data handling terms. Some products preserve a privacy promise only for a specific endpoint or plan tier, while fallback routing, tool use, or optional integrations can change the path that the document takes. When the document must remain tightly bounded, the safest choice is usually a private deployment, dedicated tenancy, or enclave-style path with explicit trust-boundary controls.
For a practitioner-facing view of where AI services fail in practice, NHIMG’s McKinsey AI platform breach and DeepSeek database exposure 2025 are useful reminders that exposed chat history, logs, and secret material are often the real failure modes, not just model output quality.
What should teams verify before sending confidential text?
First, verify the vendor’s data retention terms in writing, including whether prompts, outputs, attachments, and metadata are stored separately. Second, check whether opt-out from training is default, account-scoped, or contract-dependent. Third, confirm upload size limits, file parsing behavior, and whether documents are chunked, indexed, or processed by retrieval components that may create additional copies.
File handling deserves special attention because an LLM API rarely receives “just text” in real use. Documents may be converted into OCR text, embeddings, temporary files, search indexes, or audit logs. Each of those can become a secondary storage location, which matters if your policy requires deletion, regional residency, or strict need-to-know controls.
The most relevant external guidance here is the NIST AI 600-1 GenAI Profile, which is useful for thinking about data provenance, governance, and operational boundaries around generative AI use. For API-mediated access paths, the OWASP API Security Top 10 is also relevant because broken authorization and excessive exposure often show up at the integration layer rather than in the model itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack surface, NIST AI 600-1, CIS Controls v8 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI 600-1 | Generative AI Profile | GenAI handling of prompts, retention, and governance materially affects confidential document use. |
| Recommendation — Apply GenAI governance controls to define retention, provenance, and disclosure requirements before uploading confidential text. | ||
| OWASP API Security Top 10 | API8 — Security Misconfiguration | API routing, storage defaults, and exposure controls determine whether confidential prompts stay bounded. |
| Recommendation — Validate API configuration, retention defaults, and access paths before approving confidential document traffic. | ||
| CIS Controls v8 | CIS-3 — Data Protection | Confidential document handling depends on protecting stored content, logs, and secondary copies. |
| Recommendation — Classify, restrict, and monitor confidential content wherever the API workflow stores or processes it. | ||
| ISO/IEC 27001:2022 | A.5.12 — Classification of information | Confidential document selection depends on matching provider handling to information sensitivity. |
| Recommendation — Classify the document first, then select only providers whose handling matches the required sensitivity level. | ||
| NIST CSF 2.0 | PR.DS-01 — Data-at-rest is protected | Storage and retention risk are central to confidential document processing decisions. |
| Recommendation — Require protection of stored prompts, uploads, and derived artifacts before using the API for sensitive content. | ||
Practitioner Guidance
What to prioritise: Choose the provider after you have a written answer to three questions: whether the prompt is stored, whether it can be used for training, and whether routing ever leaves the intended boundary. If the answers are unclear, treat that as a selection failure, not a documentation gap.
Decision rule: If the document is confidential but can tolerate controlled processing, a documented no-training path with strict retention limits may be acceptable. If the document must not cross your trust boundary at all, use a private model, dedicated tenancy, or enclave-based deployment instead of a general-purpose public router.
What to verify: Ask for the exact treatment of uploads, logs, backups, support access, and retention deletion, then test it with a non-sensitive sample before approving real documents. Also verify whether the same policy applies to every model behind the API, not just the marketing headline.
Common mistake: Teams often equate “not trained on” with “not retained,” or assume a secure UI workflow extends to the API path. Those are different controls, and either one can be the weak point.
Practitioner takeaway: For confidential documents, the right LLM API is the one whose data path you can explain end to end, because confidentiality fails when storage, logs, routing, or retention are left to implicit defaults.
Related resources from NHI Mgmt Group
- Why does sending sensitive data to LLM APIs create risk even when the provider does not use API data for training?
- Why does inline enforcement matter for API security when teams are also deploying LLM features?
- How should teams choose an LLM for code generation when security and compliance matter most?
- How should teams choose a Kubernetes deployment strategy when uptime, rollback speed, and release risk all matter?