The router may avoid storing the prompt, but privacy is still incomplete because the upstream provider receives the text and may retain it under its own policy. That creates a split trust model that many teams miss. Treat the router as one control point, then approve each upstream model host before sending customer documents through that path.
What actually changes when the PDF leaves your router
The key issue is that a router is not the same as the upstream model host. It may terminate or proxy the request, but the model provider still sees the document content, and that provider can apply its own retention, logging, abuse-prevention, and human-review policies. The practical consequence is a split trust boundary: the router may be one control point, but it is not the only one.
That matters most when the document contains customer information, legal material, regulated data, or anything you would not want stored outside your approved processing chain. A privacy review has to follow the data path, not stop at the first intermediary.
Why “router-only” review creates a false sense of privacy
Teams often assume the router’s promise, such as “we do not store prompts,” is enough to satisfy a confidentiality review. In reality, that promise says little about what happens after the upstream provider receives the text. If the provider persists the request, trains on it, or uses it for monitoring, the confidentiality posture changes even when the router itself is well behaved.
That is why approval must be provider-specific. You are not only selecting a route, you are selecting a processing policy, a retention model, and a third-party trust boundary. If those terms are not reviewed before the first confidential PDF is sent, the organisation is effectively accepting hidden downstream handling terms by default.
What a safe approval path should cover
A good approval process checks three things: where the content is sent, how long it is retained, and whether the upstream provider can use it beyond the immediate inference request. For sensitive PDFs, the reviewer should also confirm whether the provider supports enterprise terms, data segregation, no-training commitments, and administrative controls over logging and retention.
One useful way to think about the control is to separate transport assurance from content-handling assurance. The first says the router is technically functioning; the second says the upstream host is acceptable for the document type. Both have to be true before the path is defensible.
Risk and Threat Considerations
Confidential documents can leak through ordinary AI handling paths even when no one intends to expose them. The main risk is hidden persistence or reuse by an upstream provider that the team never reviewed, which can turn a convenient workflow into an unauthorised disclosure channel.
Failure mechanism: A trusted router forwards the PDF to a model host whose retention, logging, review, or secondary-use policy was never approved for that content class. The exposure is created by the upstream processing relationship, not by the router alone.
Impact: Sensitive document contents may be retained outside the intended boundary, broadening access, complicating incident response, and creating contractual, regulatory, or customer-trust problems after the fact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-22 — Publicly Accessible Content | Routing confidential PDFs to upstream hosts is a content-distribution decision. |
| AU-11 — Audit Record Retention | Upstream providers may retain prompts or document text beyond the router boundary. | |
| Recommendation — Restrict disclosure paths and approve each content-sharing channel before sending sensitive documents. Set retention limits and verify how long upstream services keep transmitted document content. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | The upstream model host is a third-party processing dependency that needs approval. |
| A.5.23 — Information security for use of cloud services | Model routing often relies on cloud-hosted AI services with separate provider controls. | |
| Recommendation — Assess supplier handling terms before allowing confidential PDFs through the model path. Approve cloud AI services for the intended data class and confirm their retention and logging settings. | ||
| NIST CSF 2.0 | GV.SC-01 — Supply Chain Risk Management Policy | The question hinges on third-party provider review before sending sensitive content. |
| Recommendation — Apply supplier-risk review before routing confidential documents to external model hosts. | ||
Practitioner Guidance
What to prioritise: Classify the document before routing it. If the PDF contains customer data, legal material, or regulated information, require explicit upstream approval rather than treating the router as the final control.
What to verify: Confirm the upstream host’s retention, training, logging, and human-review terms for the exact data class you intend to send. If you cannot answer those questions in writing, do not treat the path as approved.
Decision rule: If the router and the upstream provider are different organisations or policies, review both. If either side cannot support the required handling terms, use redaction, a different host, or a narrower workflow.
Practitioner takeaway: The safe mental model is not “router approved, therefore safe,” but “each processing hop approved, therefore safe.”
Related resources from NHI Mgmt Group
- What happens when a bias-mitigated model is deployed through an API without proper input validation?
- What happens when PHI is sent through a document platform without the required HIPAA controls?
- What happens when organisations rely on a custom OIDC provider without aligning it to their access governance model?
- What happens when teams connect a model provider without aligning it to their identity and security controls?