OpenRouter AI data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On OpenRouter AI, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenRouter AI connector needs.
Checks (9)
severity: high Prompt/Response Logging Enabled fix difficulty: medium #
Disable prompt/response logging unless required and lawful
- Open the workspace's observability settings
- Disable I/O logging, or document a lawful basis and retention limit
Satisfies: SOC 2 Type II CC4.1 GDPR (SaaS Security) GDPR-5.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Logging At Full Sampling fix difficulty: easy #
Reduce I/O logging sampling below 100%
- Open the workspace's observability settings
- Lower the sampling rate to the minimum needed for debugging
Satisfies: SOC 2 Type II CC4.1 GDPR (SaaS Security) GDPR-5.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Observability Broadcast Enabled fix difficulty: easy #
Review observability broadcast for the workspace
- Open the workspace's observability settings
- Disable broadcast if not required
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Data-Discount Logging Enabled fix difficulty: easy #
Disable data-for-discount logging on the workspace
- Open the workspace's settings
- Disable the data-discount logging option
Satisfies: SOC 2 Type II CC5.3 GDPR (SaaS Security) GDPR-25.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high LLM Data Exported To External Sink fix difficulty: medium #
Review and restrict export of LLM prompt/response data
- Open the workspace's observability destinations
- Remove or restrict destinations that egress data to third-party or self-hosted sinks
Satisfies: SOC 2 Type II CC6.7 GDPR (SaaS Security) GDPR-28.3 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Guardrail Without Zero Data Retention Enforcement fix difficulty: medium #
Enable Zero Data Retention enforcement on the guardrail
- Open the guardrail in the workspace settings
- Enable Zero Data Retention enforcement for each provider scope in use
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Guardrail With Partial Zero Data Retention Enforcement fix difficulty: medium #
Extend Zero Data Retention enforcement to the remaining provider scopes
- Open the guardrail in the workspace settings
- Enable Zero Data Retention enforcement for every provider scope, not only some
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Guardrail Allows Training Data fix difficulty: easy #
Disable model training and free-model publication on the guardrail
- Open the guardrail in the workspace settings
- Disable free/paid model training and free-model publication options
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Permissive Privacy Posture fix difficulty: medium #
Restrict routing to providers that may train on or log data
- Open account privacy settings
- Disable routing to providers that may train on or log data
Satisfies: SOC 2 Type II CC5.3 GDPR (SaaS Security) GDPR-25.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11