| Provider account boundary | Use customer-provided credentials or self-hosted provider routing for strict boundary control |
| Data retention mode | Use provider zero-retention mode where eligible and contractually enabled |
| Training controls | Keep provider training opt-in disabled for API data |
| Prompt scope control | Limit prompts to minimum task-relevant context and avoid unrestricted raw payload submission |
| Secret management | Store provider credentials in managed secret stores with scoped runtime access |
| Key lifecycle | Rotate provider credentials on a defined cadence and on any incident trigger |
| Network controls | Restrict outbound destinations to approved AI provider endpoints |
| Auditability | Log AI request metadata and outcome events without exposing sensitive prompt text in operational logs |