Skip to content

How we approach data privacy at the model layer

Priya Desai · 1 min read · March 18, 2026

How we approach data privacy at the model layer

Privacy at the model layer isn’t a feature you can add later. It’s a posture you decide on day one. Here’s how we approached it.

The threat model

Customer data flowing through an AI workload can leak in three places: the request, the model’s training data, and the response logs. Each has its own controls, and “we’re SOC 2” is not a sufficient answer for any of them.

What we actually do

Customer prompts and responses are encrypted in transit and at rest. They never enter our training pipeline. They’re scoped to the customer’s tenant, with audit logs available on request.

The hardest part wasn’t the technology. It was building the discipline to say no when product asked for “just a little” cross-tenant analytics.

Compliance + something more

SOC 2 Type II, GDPR, HIPAA, ISO 27001 — we’re certified across the board. But the more useful question we ask ourselves: would we let our own engineers read this data? If the answer is no, our customers shouldn’t have to either.

FILED UNDER Security
SHARE
Priya Desai
WRITTEN BY

Priya Desai

NeuralPress · Security

/ JOIN THE CONVERSATION

Leave a comment.

Add your thoughts

Your email won't be published. Required fields are marked with an asterisk.