AI vendor security reviewAI Vendor Security Review: 6 Questions That Change the Answer
Six questions decide an AI vendor security review, and a SOC 2 report answers none of them. How OpenAI, Anthropic, Microsoft, Google and Amazon Bedrock answer each, as of September 2026.
September 12, 2026 · 20 min readCursorOpenAI Cuts Cursor Off Nov 12. BYOK Voids Your ZDR.
OpenAI stops serving its models to Cursor on 12 November 2026. Pointing Cursor at your own OpenAI key is not a swap — Cursor's documentation says its Zero Data Retention policy does not apply to custom keys, and every request still routes through Cursor's backend.
August 30, 2026 · 12 min readzero data retentionFable 5 Needs Retention On. ZDR Was Never Zero.
Claude Fable 5 and Mythos 5 are Covered Models: they refuse to run in a zero-data-retention workspace on the Claude API, Bedrock, Google Cloud or Microsoft Foundry. Anthropic's own docs also say flagged prompts can be held up to two years even under ZDR — while OpenAI previews the opposite bet.
August 20, 2026 · 13 min readOpenRouterStripe Bought OpenRouter. A Toggle Is Not a Contract.
Stripe is reportedly paying over $7 billion for the gateway 8 million developers route prompts through. Its privacy toggles bind the downstream model providers, not OpenRouter itself — and the only DPA anybody countersigns is enterprise-tier.
August 17, 2026 · 13 min read