Skip to content

OpenRouter AI data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On OpenRouter AI, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenRouter AI connector needs.

Checks (9)

severity: high Prompt/Response Logging Enabled fix difficulty: medium #

Disable prompt/response logging unless required and lawful

  1. Open the workspace's observability settings
  2. Disable I/O logging, or document a lawful basis and retention limit

Vendor docs ↗

Satisfies: SOC 2 Type II CC4.1 GDPR (SaaS Security) GDPR-5.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Logging At Full Sampling fix difficulty: easy #

Reduce I/O logging sampling below 100%

  1. Open the workspace's observability settings
  2. Lower the sampling rate to the minimum needed for debugging

Vendor docs ↗

Satisfies: SOC 2 Type II CC4.1 GDPR (SaaS Security) GDPR-5.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Observability Broadcast Enabled fix difficulty: easy #

Review observability broadcast for the workspace

  1. Open the workspace's observability settings
  2. Disable broadcast if not required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Data-Discount Logging Enabled fix difficulty: easy #

Disable data-for-discount logging on the workspace

  1. Open the workspace's settings
  2. Disable the data-discount logging option

Vendor docs ↗

Satisfies: SOC 2 Type II CC5.3 GDPR (SaaS Security) GDPR-25.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high LLM Data Exported To External Sink fix difficulty: medium #

Review and restrict export of LLM prompt/response data

  1. Open the workspace's observability destinations
  2. Remove or restrict destinations that egress data to third-party or self-hosted sinks

Vendor docs ↗

Satisfies: SOC 2 Type II CC6.7 GDPR (SaaS Security) GDPR-28.3 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Guardrail Without Zero Data Retention Enforcement fix difficulty: medium #

Enable Zero Data Retention enforcement on the guardrail

  1. Open the guardrail in the workspace settings
  2. Enable Zero Data Retention enforcement for each provider scope in use

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Guardrail With Partial Zero Data Retention Enforcement fix difficulty: medium #

Extend Zero Data Retention enforcement to the remaining provider scopes

  1. Open the guardrail in the workspace settings
  2. Enable Zero Data Retention enforcement for every provider scope, not only some

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Guardrail Allows Training Data fix difficulty: easy #

Disable model training and free-model publication on the guardrail

  1. Open the guardrail in the workspace settings
  2. Disable free/paid model training and free-model publication options

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Permissive Privacy Posture fix difficulty: medium #

Restrict routing to providers that may train on or log data

  1. Open account privacy settings
  2. Disable routing to providers that may train on or log data

Vendor docs ↗

Satisfies: SOC 2 Type II CC5.3 GDPR (SaaS Security) GDPR-25.2 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

More OpenRouter AI checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial