> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Data privacy and security

> Control what Orq.ai stores from traces, how long observability data is kept, and which compliance, secret and access controls apply to a workspace.

**AI Observability** stores traces, spans and logs so they can be debugged, evaluated and reviewed. The pages below cover keeping sensitive content out of stored traces, how long observability data is kept, and the compliance, residency and access controls that apply.

## Keep sensitive content out of stored traces

<CardGroup cols={2}>
  <Card title="Trace Scrubbing" icon="eraser" href="/ai-gateway/features/plugins/trace-scrubbing">
    Mask selected fields in stored traces using the `trace_scrubbing` plugin.
  </Card>

  <Card title="Trace Data Masking" icon="eye-slash" href="/ai-gateway/features/security">
    Control which request and response content is written to stored traces, without changing live output.
  </Card>

  <Card title="PII Redaction" icon="user-shield" href="/ai-gateway/features/plugins/pii-redaction">
    Redact personally identifiable information before requests reach the provider, then restore values in the response.
  </Card>

  <Card title="Deployment Security and Privacy" icon="lock" href="/ai-studio/ai-engineering/deployments#security-and-privacy">
    Flag deployment inputs as PII or enable output masking, so logs and traces store neither.
  </Card>
</CardGroup>

## Data handling and access

<CardGroup cols={3}>
  <Card title="Data Retention" icon="clock" href="/ai-studio/organization/data-retention">
    How long observability data is kept per plan, and how automatic deletion works.
  </Card>

  <Card title="Data Compliance" icon="scale-balanced" href="/ai-studio/organization/data-compliance">
    Data handling, privacy practices and the standards Orq.ai is audited against.
  </Card>

  <Card title="Secrets" icon="key" href="/ai-studio/organization/secrets">
    Where API Keys, provider credentials and signing secrets are stored, who can read each one, and how to rotate it.
  </Card>

  <Card title="Workspace Security" icon="shield" href="/ai-studio/organization/workspace-security">
    Verify domain ownership with DNS TXT records and restrict access with an IP allowlist, on the Enterprise plan.
  </Card>

  <Card title="Audit Logs" icon="clipboard-list" href="/ai-studio/organization/audit-logs">
    Track who changed what in a workspace, for compliance and security reviews.
  </Card>

  <Card title="Sovereign AI & ZDR" icon="globe" href="/enterprise/sovereign-ai">
    AI sovereignty across business entity, EU infrastructure, model routing and zero data retention.
  </Card>

  <Card title="EU Routing & Data Residency" icon="map-pin" href="/enterprise/eu-regions-faq">
    Where platform data is stored by default and how EU routing and sovereign deployments change it.
  </Card>
</CardGroup>
