So it is a security threat in one sense, you’re trusting another company with that information.
And most providers, aside from when you’re buying a business contract or like a business plan, they’re going to be keeping your data for 30 days minimum. And if they’re not keeping your data, they’re going to be using your data to train with.
So there’s multiple layers to this. So the way I see it is you have about two or three layers.
Tier one: the provider trains on your data
Layer number one is the AI provider uses your data for training. So the first layer is training and using your data to train their models.
They’ll have maybe a team come in or most likely another AI and they’ll review your document, see what it says and see how they can use your information to make the model better.
You may feel like this is scoped just to AI, but as we continue to get more specific AIs in more specific industries, we’ll have the case where we have AI trained just for your industry. So if they’re using your trade secrets to train an AI for your industry, then your trade secrets will become everyone’s trade secrets.
So in that respect, tier one is dangerous for companies putting their information in to these providers that use your data to train AI.
Tier two: no training, but they keep your data
And so this one’s better, right? It’s not tier three or the last tier, the most secure, but it’s tier two. And what this says is that they do not use that data to train their models.
But what they do is they keep your data for 30 days and they have a pretty general, in my opinion, pretty general allowance on whether they get to review that data and if they need to hold on to that data for an incident or whatever that means.
It gives them in my opinion a lot of liberty about what they can do with your data, how long they can hold on to it. And if they deem it to be reviewable or something they need to keep and held on to, they can.
Tier three: zero data retention
The last tier is a zero data holding policy, and there’s a few really good providers for this. I’m using fireworks.ai right now. They have by default a zero retention policy and they are an API provider.
The downside of this provider is that they only have open source models. So they didn’t develop the model themselves. What they do is they take models that are existing out there that people are giving away for research purposes or for free, and they’re hosting it on their platform and then providing it as a service.
What I like about that is that the open source models are getting pretty good. One benefit of the open source model is that anyone can use it.
And so this company, Fireworks AI, what they do is they allow you to use that model without retaining any of the data. So once your request, once your documents go to them, they will process it, have the AI work on your documents, send the response, and delete the request.
So that’s a really good use case for companies that want to prioritize this data security. Yes, your data is going out and coming back.
Phase three of providers is a zero data retention policy. So that’s what I would look for when you’re evaluating these API needs.