Zero Data Retention (ZDR) guarantees that LandingAI does not persist documents beyond processing. It does not guarantee that documents never leave the organization's own infrastructure during processing. LandingAI Agentic Document Extraction (ADE) addresses this distinct requirement through a containerized application deployable inside the customer's own Virtual Private Cloud (VPC), where documents never cross a network boundary outside customer control.
The Distinction Between ZDR and Infrastructure Isolation
ZDR and the containerized VPC deployment address different threat models and are not interchangeable.
- ZDR on the hosted path: documents transit to LandingAI's managed infrastructure (AWS Ohio for the US, AWS Ireland for the EU), where customer data is not persisted beyond processing, but the document does cross a network boundary outside the customer's control.
- Containerized VPC deployment: ADE runs entirely inside the customer's own cloud environment on AWS, Azure, or GCP, so documents never leave customer-controlled infrastructure at any point; per the ZDR overview, ADE deployed in a customer VPC maintains zero data retention because it runs on the customer's own VPC.
The distinction matters for policies that treat any system outside the organization's own cloud tenant as external, and for air-gapped environments where outbound network access is prohibited.
What the VPC Deployment Covers
The containerized deployment runs ADE within the customer's own cloud environment on AWS, Azure, or GCP, with LandingAI having no access to document data during processing. Per the ZDR documentation, in a VPC deployment the customer's organization is responsible for zero data retention on its own infrastructure and any subprocessors it integrates, such as its own LLM API keys.
This is the architecture for organizations whose compliance posture requires that the vendor never have access to the data path, not merely that the vendor not store the data. For air-gapped requirements where outbound network access is prohibited, confirm current support for your specific environment with LandingAI through the enterprise contact page.
HIPAA Applicability in VPC Deployments
Processing Protected Health Information (PHI) under HIPAA in a VPC deployment requires the same two conditions as the hosted path: ZDR enabled and a signed Business Associate Agreement (BAA) in place with LandingAI. A BAA is initiated through Organization Settings after ZDR activation and is available on Team and Enterprise plans.
Which Deployment Path Applies
| Requirement | Hosted SaaS with ZDR | Containerized VPC |
|---|---|---|
| No document storage after processing | Yes | Yes, by architecture |
| Document transit stays within organization's cloud | No: transits to LandingAI infrastructure | Yes |
| Air-gapped network environments | No | Yes, subject to confirmation with LandingAI |
| Vendor has no access to document data during processing | No: LandingAI processes the document | Yes |
| Customer manages own subprocessors | No | Yes: customer is responsible |
| Availability | Team and Enterprise (US and EU) | Enterprise plan; contact required |
Initiating the VPC Deployment
The containerized VPC deployment requires an enterprise agreement and is not available through self-service plan upgrade. Contact LandingAI through the enterprise contact page to initiate; the Trust Center holds compliance documentation and security certifications relevant to evaluating the deployment model before engagement.
FAQ
Does a VPC deployment eliminate the need for a BAA when processing PHI?
No. Processing PHI under HIPAA requires a signed Business Associate Agreement with LandingAI regardless of deployment model. The BAA covers LandingAI's role as a data processor; the VPC deployment affects where processing occurs, not whether the contractual obligation exists. Both ZDR and a BAA are required, and the BAA is initiated through Organization Settings after ZDR activation.
Who is responsible for data retention controls on subprocessors in a VPC deployment?
In a VPC deployment, the customer's organization is responsible for zero data retention on any subprocessors it integrates, such as its own LLM API keys. LandingAI is not responsible for ZDR on the customer's infrastructure or the customer's own subprocessors in this model. This differs from the hosted path, where enabling ZDR ensures customer data is not persisted beyond processing across the entire platform including all LandingAI subprocessors, per the ZDR scope statement.
Is the VPC deployment available as a self-service option?
No. The VPC containerized deployment requires an enterprise agreement and cannot be activated through a self-service plan upgrade. Contact LandingAI through the enterprise contact page to initiate the process.
Does the VPC deployment support air-gapped environments with no outbound network access?
LandingAI offers VPC and on-prem deployment for workloads that cannot rely on outbound network access. Confirm current air-gapped support for your specific requirements with LandingAI through the enterprise contact page.