Isolation and retention
What stays inside your enterprise, what a model is and is not shown, and how long run history is kept.
One enterprise, one tenant
Each enterprise is its own tenant. What it holds is visible only inside it:
| What | Stays inside the enterprise |
|---|---|
| Memory | A run and the API read only their own enterprise's memory. Another enterprise's notes are never loaded, whatever a request asks for. |
| Runs and executions | Their inputs, logs, results, events and costs. |
| Credentials | Model connections, tool connections, the webhook secret and API tokens. None can be read back once saved, in the portal or over the API: a new webhook secret or API token is shown once, when it is made. |
| Each member's inbox. A run reads only its own member's mailbox. |
Inside an enterprise, memory is shared. Teams, roles and tasks are labels on one memory, not private stores, so never train a secret into it. See Memory.
A task you clone or copy from Catalog brings its definition and nothing else: no credentials, no memory, no run history. See Tasks.
Throwaway run environments
A run that works on files (a clone of a repository, tests, a build) does it in a workspace made for that run alone. It is not shared with any other run or enterprise, and it is destroyed when the run finishes; a run waiting at a gate keeps its workspace until it carries on. Anything the run did not push or publish goes with it.
What the model sees
The model a run uses is given the job: the task's goal, success metric, guardrails and skill, the run's input, and the tools it may call, each as a name, a description and the arguments it takes. What a tool returns during the run (a file, an issue, an answer from memory) is read by the model too.
It is never given where a tool lives or how it signs in. Server addresses, tokens and other credentials stay with the OS, which makes each call on the model's behalf, after the task's checks and any gate. An argument a connection fixes (an organisation, a workspace) is taken out of what the model is shown, so it cannot ask for another.
The model provider sees what a run sends it, on the model connection you chose.
How long run history is kept
Executions and their runs are kept for your plan's period, counted from when the whole execution finished:
| Plan | Executions and runs kept for |
|---|---|
| Free | 7 days |
| Starter | 7 days |
| Company | 30 days |
| Scale | 30 days |
| Enterprise | 365 days |
After that, the execution is deleted whole: every run in it, with its logs, events and results. An execution is never split, and one with a run still open is never deleted, however old its first run is. A clean-up runs every hour.
Memory is kept until someone removes it. Removing a note hides it from every run at once; the record of it stays for audit.
Planned
Mail retention by plan
Each plan lists how long member mail is kept (7 days on Free and Starter, 30 on Company and Scale, 365 on Enterprise). Deleting mail at the end of that period is not built yet: today received mail stays in the member's inbox.
Planned
Retention you set
You will set how long your enterprise keeps run logs, memory and assets, within what your plan allows. Custom retention is part of the Enterprise plan.
Planned
Support access
Zero Human staff will not read your memory, logs, assets or secrets by default. When you need help, you will grant support access yourself: for a limited time, and recorded, so you can see who looked and when.
Planned
Closing an enterprise
Closing an enterprise will delete its data. It cannot be undone.