Guide 4 min read

Zero retention: what it means in our architecture, line by line

The phrase is used loosely across the industry. Here is what it means in ZAAN's request path, what persists and why, what it does not mean, and the questions to ask any vendor.

2025 · 11 · 20·admin

“Zero retention” appears on most legal-technology security pages, including ours. It is rarely defined. This guide follows a single document through our systems and states, at each step, what is kept, for how long, where, and who can read it. It then lists what the phrase does not mean, because the gaps are where buyers get surprised.

The request path

1. The document leaves the firm. A reviewer opens a draft in Word with the ZAAN add-in, or Recall ingests a document from the DMS connector. The content is encrypted in transit with TLS 1.3 to the endpoint of the tenant’s chosen region: CH, EU, US or SG. There is no global endpoint. DNS resolves to the region; the other three regions have no route to the tenant’s data.

2. It arrives in a tenant-scoped process. Each tenant’s requests are handled by processes with a tenant-specific encryption context. Keys are per tenant, held in a hardware security module in the region, and the tenant can bring and revoke its own key. A process holding tenant A’s context cannot decrypt tenant B’s data. This is per-tenant encryption, and it is enforced at the key level, not by application logic alone.

3. The model reads it. Review, Draft and Recall call ZAAN-7B Counsel, and for some background tasks a larger model, hosted inside the same region. The inference servers have no persistent storage mounted. Prompts and completions are held in memory for the duration of the request and overwritten when the request completes. Inference logs record request ID, tenant ID, model version, timing and token counts. They do not record prompt or completion text. We verify this with a quarterly audit that samples inference logs and confirms no content fields exist; the auditor’s report is available under NDA.

4. The response returns. The flag, redline or answer is encrypted with the tenant context and sent back. The request-handling process releases its memory. Nothing from the request is written to any store at this step.

5. The audit log is written. Who, when, which action, which document identifier, which model version, whether a flag was accepted or declined. The document identifier is the tenant’s own, and the log does not include clause or document text. Audit logs are retained in region for the period the tenant configures (default 13 months) and are readable by the tenant’s administrators and, under a documented access procedure, by our security team.

That is the whole path for a Review or Draft request. Zero retention, for us, means that steps 3 and 4 write nothing and that step 5 writes no content.

What persists, and why

The tenant’s own index. Recall is a search product; a search product that retains nothing cannot search. The index of a firm’s matter history is stored in region, encrypted per tenant, under the tenant’s key if they hold one. It is the firm’s data, in the firm’s vault, and the firm controls ingestion, deletion and the ethical walls enforced on top of it. This is retention, by design and under the tenant’s control, and it is not what “zero retention” refers to. We say so in the contract.

Matter state. Settled rejections from Review 4.0, playbooks, whitelists, Simulation run histories and intake briefs from AI Interview are tenant data stored in the same way.

Backups. The tenant index and matter state are backed up within region, encrypted with the same tenant key. Backups are retained for 35 days and are purged on tenant deletion within that window. There is no backup of inference traffic because there is no inference traffic stored.

Crash dumps. Process crash dumps can capture memory, and memory can contain content. Dumps are generated in region, scrubbed of all heap regions tagged as tenant content before being written, and deleted after seven days. The scrubber is tested on every build with seeded content.

What zero retention does not mean

  • It does not mean we keep nothing. It means the processing path keeps nothing. The firm’s vault keeps what the firm puts in it.
  • It does not mean no logs. It means logs without content. Metadata is retained because audit without metadata is not audit.
  • It does not mean nobody can ever see tenant data. A support engineer, with the tenant administrator’s time-limited grant and a logged justification, can be given read access to a specific matter in the tenant’s vault to resolve a defect. This happened 14 times across all tenants in the first three quarters of 2025. Every instance is in the tenant’s audit log.
  • It does not mean no training. It means no training on tenant data. That is a separate commitment, the no-train guarantee, and the training manifest for ZAAN-7B Counsel is the evidence for it.
  • It does not mean no subprocessors. Infrastructure in each region is provided by cloud operators under data-processing terms. They hold encrypted blocks they cannot read. The list is published and changes are notified 30 days ahead.

Questions to ask any vendor

  • Where exactly does the content exist in plaintext, and for how long?
  • Do inference logs contain prompt or completion text? Who checked?
  • Is per-tenant encryption enforced by key separation or by application code?
  • Can I bring and revoke my own key, and what happens to backups when I do?
  • Can a support engineer read my documents, under what procedure, and will I see it in my log?
  • What is in a crash dump?
  • Which region answers my request, and can it ever fail over to another?

If a vendor cannot answer the first question without a meeting, the phrase on their security page is doing more work than their architecture is.

See it on a contract you have already reviewed.

Send us a draft your team has already redlined and we will show you what ZAAN catches, and what it misses.