OpenAI Private Intelligence: set up Private Safety Processing
How Zero Data Retention with Private Safety Processing works in the OpenAI API, how an admin turns it on per project, and what it covers when Codex sends code.

This research library uses AI-assisted source research and drafting. Linked sources support product claims; analysis and proposed exercises are our interpretation. Unless an article documents a test and its results, do not read it as a hands-on review or an independently verified benchmark.
OpenAI Private Intelligence is the data protection offer OpenAI announced at DevDay on 29 September 2026. The part you can use today is Zero Data Retention with Private Safety Processing (PSP): automated safety review runs on your API traffic without OpenAI keeping a copy of the content and without OpenAI personnel reading it. The setup is documented in the Private Safety Processing guide, and a Private Inference preview is announced for this fall.
What OpenAI Private Intelligence includes today
Two things carry the Private Intelligence name. Only one of them has setup documentation right now.
| Component | Status on 29 September 2026 | What it does |
|---|---|---|
| ZDR with Private Safety Processing | Available to ZDR-approved API orgs | Keeps safety review automated, stores selected records encrypted in your own cloud bucket for 30 days |
| Enterprise Key Management (EKM) | Optional, recommended by OpenAI | Adds an outer encryption layer controlled by your own key management service |
| Private Inference | Preview announced for this fall | Confidential computing with strict, verifiable controls; setup details are not documented yet |
OpenAI has an interest form for Private Intelligence. Pricing for PSP is not stated on the guide page.
How Private Safety Processing handles a request
The system has two flows. The first one decides what gets retained. An interaction, meaning your prompt and the model response, is selected by a safety classifier referral or by an approved sampling policy. OpenAI states that a referral does not establish a policy violation.
A selected record is encrypted and written to your regional cloud storage. OpenAI keeps an index with operational metadata and a storage reference, not the content itself. Encryption and storage run asynchronously, so they do not block inference.
The second flow is the safety pipeline. It pulls encrypted records from your bucket into the Safety Review Runtime. That runtime is a hardware-attested environment that disables human access, and OpenAI designs it as the only workload that can decrypt your content.
Only predefined safety signals and approved operational metadata leave the runtime in plaintext. Detailed results are encrypted again and stored in your bucket with the same expiration as the original record.
Each stored record has two encryption layers. The inner layer is OpenAI-managed HPKE, which limits decryption to the safety runtime. The outer layer is your EKM key. With EKM enabled, OpenAI's key alone cannot decrypt a record. Revoking your key authorization stops decryption, but it does not delete records or undo processing that already happened.
Who can request zero data retention with PSP?
Zero data retention on the OpenAI API is not self-serve. The API data controls page says these controls need prior approval by OpenAI and acceptance of extra requirements, and it points you to the sales team. Organizations that already have ZDR approval can set up PSP directly in the API console.
Check these points before you start:
- An organization administrator must register and validate storage. For the Management API you need an organization Admin API key; a project inference key will not work.
- Pick a storage region that matches your project's data residency. You also need rights to create storage and delegate access in your cloud account.
- ZDR covers endpoints such as
/v1/responses,/v1/chat/completions,/v1/embeddingsand/v1/realtime. Endpoints that keep state until deleted, like Assistants, Threads, Vector Stores and Conversations, are not eligible. - Under ZDR, the
storeparameter on/v1/responsesand/v1/chat/completionsis always treated as false.
How to enable Private Safety Processing on a project
PSP is switched on per project, not per request. Once it is active, the PSP policy applies to all API traffic in that project, including models that do not require PSP. If you want ZDR without PSP for eligible models, OpenAI says to send that traffic through a separate project.
- Create a dedicated bucket in AWS S3, Azure Blob Storage, or Google Cloud Storage. On S3, keep ACLs disabled and block all public access. With Data Residency off, OpenAI recommends
us-west-1. - Add a lifecycle rule that deletes objects under the
openai/prefix after 30 days. Make sure no other rule deletes them earlier. - Grant OpenAI access. On AWS that is an IAM role trusting the OpenAI principal, with your OpenAI project ID as the external ID. Azure uses the OpenAI application with Reader and Storage Blob Data Contributor roles. GCP uses workload identity federation and a custom storage role.
- In the API console, open Organization settings, then Data controls, then Data retention, and select Connect storage. Choose the provider and project, enter the bucket details, and select Connect and validate.
- Wait for Storage validated and a project policy that reads Zero Data Retention with Private Safety Processing.
If you script it, the Management API registers storage and then validates it. This is the AWS registration call from the guide:
curl --fail-with-body -sS -X POST "$OPENAI_STORAGE_URL" \
-H "Authorization: Bearer $OPENAI_ADMIN_KEY" \
-H "OpenAI-Organization: $OPENAI_ORG_ID" \
-H 'Content-Type: application/json' \
--data-binary '{
"project_id": "CUSTOMER_PROJECT_ID",
"provider": {
"type": "aws",
"bucket": "CUSTOMER_BUCKET_ARN",
"role_arn": "CUSTOMER_ROLE_ARN"
}
}'
The response returns an ID that starts with extstorage_ and a pending status. Registration alone does not change the project policy. You then call the /validate endpoint for that ID, and a validated status activates customer-managed retention.
Validated records one successful check. It is not live monitoring, and Refresh in the console reloads the saved status without testing the connection again.
What PSP means for code you send from Codex
Your Codex sign-in method decides which policy covers your code. The Codex authentication docs say ChatGPT sign-in follows your ChatGPT workspace permissions and Enterprise retention and residency settings. With an API key, usage follows your API organization retention settings and bills at standard API rates.
So a PSP project only covers Codex sessions that use a key from that project. The docs show the key login like this:
printenv OPENAI_API_KEY | codex login --with-api-key
A practical setup for a regulated repository looks like this. Create one API project for coding agent traffic, enable ZDR with PSP on it, and issue Codex keys only from that project. Keep experiments that do not need PSP in a different project, because the policy covers everything in the PSP project. The docs also note that some enterprise features are limited or unavailable with API key sign-in, so confirm the ones your team relies on.
Remember what a sampled record contains. If Codex sent a file with a hardcoded credential, that content sits encrypted in your bucket for 30 days. Treat the bucket with the same access rules as the repository itself. We teach the same habit in our review methodology: decide the data boundary before the agent runs, then check it in review.
What you must keep running after go-live
OpenAI lists ongoing customer duties for ZDR with PSP:
- Register and validate storage for each PSP-enabled project and each data residency location.
- Keep encrypted records for at least 30 days.
- Keep regional storage, service permissions and customer-managed key authorization working.
- Fix configuration problems after OpenAI notifies you.
- Work with OpenAI when it raises a safety concern.
Disconnecting the last storage connection resets the project to your organization's default retention policy. Models that require ZDR with PSP may then become unavailable. Disconnecting does not delete the bucket or its contents, so your retention duties for existing records continue.
Before you move a regulated repository onto Codex, check which sign-in method each developer uses and open the Data retention page for the matching API project.
Further reading
Related training topics
Review is one step in the methodology.
Related research

Codex mobile CLI docs your team can read anywhere
The codex mobile cli question is a docs question: how a team keeps AGENTS.md rules, run notes, and verification transcripts readable away from the desk.

Codex CLI Goal Mode, Appshots, and the Real Workflow
What Codex CLI Goal Mode and Appshots change day to day, and the AGENTS.md and verification habits that make them worth using.

Codex mobile CLI: runs that survive review
A codex mobile cli pattern for running Codex CLI from anywhere: verification latches, model pins, and connector rosters that keep remote runs reviewable.
Continue through the research archive
Newer research
OpenAI Marketplace partners for engineering teams
Which developer tools sit in the first OpenAI Marketplace partner list, what committed spend means for engineers, and how to test Codex review against them first.
Earlier research
OpenAI Ultrafast in Codex and the API: plans, setup, cost
How to get OpenAI Ultrafast for GPT-6 Astra: which Codex plans include it, the service_tier setting for the API, rate limits, and what the extra speed costs per task.