Where your data goes, and what Mizan keeps: data residency and zero data retention
A request through Mizan passes through two points: Mizan and the model provider. Here is where each one sits, what each one retains, and the settings you control.
The short version
Two questions matter when you send prompts to an AI model through a gateway: where does the data go, and does anyone keep it. For Mizan the answers are simple. You choose where your request is processed, and by default nothing is retained: not by Mizan, and not by the model providers behind it.
How a request flows through Mizan
When you send a request through Mizan, four things happen in order:
- 1Your application sends the request to Mizan.
- 2Mizan routes it to the model provider you selected.
- 3The provider generates the answer and returns it to Mizan.
- 4Mizan passes the answer back to your application.
That means your data touches exactly two points: Mizan and the provider. Residency and retention each have to be answered for both, which is why the rest of this post treats them separately.
| Mizan | Model provider | |
|---|---|---|
| Where it is processed | EU today. KSA, UAE and US coming soon. | Your choice: EU, US, KSA or UAE providers |
| What is retained | Nothing by default. Only usage metrics. | Nothing. Zero data retention by default. |
Data residency: you choose where it transits
Mizan
Mizan is currently hosted entirely in the EU. KSA, UAE and US hosting are coming soon, and when they land you will be able to select which region your data transits through.
The provider
The model catalog includes providers based in the EU, the US, KSA and the UAE, and you decide which one handles a request. Choose an EU-based provider and your data stays in the EU end to end. The same logic applies to the other regions once Mizan's own hosting is available there.
Until Mizan's KSA, UAE and US regions are live, a request to a provider outside the EU still passes through Mizan's EU infrastructure in transit on its way there. If your requirement is that data never touches the EU, that is worth knowing today.
Residency is a routing choice, not a one-time setting. For how residency can be treated as an input to every routing decision, see residency-aware routing.
Zero data retention: Mizan keeps nothing by default
Out of the box, everything that passes through Mizan is in transit only. Mizan does not keep your prompts, and it does not keep the outputs. What it does keep are metrics: token counts, cost, latency, which provider handled the call. Those are what power the dashboard, so you can see what your AI spend is doing without Mizan holding the content of your requests.
The opt-in features that do store data
Some features only work if content is stored, so they are off by default and only run if you turn them on:
- Response caching, which needs stored responses to answer repeat requests without new inference
- Souq
- Tracing, which needs stored prompts and outputs so you can inspect them later
Enabling any of them means Mizan stores the related prompts and outputs. That data is currently stored in the EU, and like the rest of the platform it will follow the multi-region rollout. If you do not enable these features, nothing is saved.
Zero data retention: providers
All of the providers on Mizan operate with zero data retention by default. Mizan does not keep your data, and the provider is not keeping it either.
Working in a sensitive field: bring your own key
If you work in healthcare, finance, government or another sensitive field, you can go a step further with BYOK (bring your own key). You connect your own provider account to Mizan, so requests run under your own agreement with that provider rather than a shared one. It is the option to reach for when you want extra assurance about exactly who handles your data.
What this doesn't replace
Residency and zero data retention are properties of how your traffic is configured. They do not decide, on their own, whether a given workload satisfies your obligations under laws like the PDPL. That determination belongs to your compliance and legal teams. What Mizan gives them is a setup that is easy to reason about: two points, a known location for each, and nothing retained unless you switch it on. For the regulatory side, see PDPL and data residency for AI.
Two points. You choose where they are. Nothing kept unless you turn it on.
AI routing, built for Saudi Arabia
Start routing your AI before complexity controls you.
Route, track and reduce your AI spend with Mizan.
Related articles
Residency-Aware Routing: Making Routing Decisions When Data Can't Leave the Country
Most AI gateways route on cost, quality, and latency. Almost none of them ask whether a request is even allowed to go where it's about to go — that's a routing decision too, and it changes how you'd build one.
Data Residency and Saudi Arabia's PDPL: What AI Teams Should Understand
A plain-language primer on why Saudi Arabia's Personal Data Protection Law is relevant to AI and LLM workloads — and the most common misconception about what it actually requires.