Azure AI Foundry

Where does this provider put your AI data — and who can compel its disclosure?

ResidencyRegion-dependent — unresolved until an endpoint region is pinned (region scheme: azure)
SovereigntyUnited States us
Endpointsservices.ai.azure.com, models.ai.azure.com
Packagesazure.ai.inference (Python), azure.ai.projects (Python), @azure-rest/ai-inference (npm), @azure/ai-projects (npm), @azure/ai-agents (npm), com.azure.ai.inference (Java), Azure.AI.Inference (.NET), Azure.AI.Projects (.NET)
KB noteFoundry project endpoints (<resource>.services.ai.azure.com) and serverless model deployments (<name>.<region>.models.ai.azure.com, region resolves via the azure scheme); serves OpenAI, Llama, Mistral, Phi, DeepSeek and more — provenance from model references

Data practices

How does this provider treat the data you send it? Advisory statements about documented practices — not legal advice.

Trains on customer API data by defaultNo source — 'Your prompts (inputs) and completions (outputs), your embeddings, and your training data ... are NOT used to train any generative AI foundation models without your permission or instruction'; 'The models are stateless: no prompts or completions are stored in the model' (retrieved 2026-08-23)
Retention (API inputs/outputs)Models are stateless: no prompts or completions are stored in the model. Stateful features (Responses API, Assistants Threads, Stored completions, Files/vector stores) persist data in the resource's Azure geography until deleted; Global and DataZone deployment types may process prompts/responses across regions within their scope. Abuse monitoring stores prompt/completion samples only when flagged, in logically separated per-resource stores; modified abuse monitoring turns this off for approved customers. source — Sections 'Generating completions...' (stateless models, geography processing incl. Global/DataZone), 'Data storage for Models sold by Azure features', and 'Preventing abuse' (flagged-sample storage, logical separation, modified abuse monitoring) (retrieved 2026-08-23)
Subprocessor listhttps://aka.ms/DPA — Microsoft Products and Services Data Protection Addendum, which governs data processing by Models sold by Azure (linked from the data-privacy article intro) (retrieved 2026-08-23)
Enterprise tierModified abuse monitoring requires application and approval; customers can verify logging is off via the ContentLogging=false capability attribute in the Azure portal/CLI. Catalog scope caveat: Foundry also serves partner/community model catalogs whose own terms may differ — verify per deployed model. source — 'How can a customer verify if data storage for abuse monitoring is off?' (ContentLogging=false); 'managed customers may apply to modify abuse monitoring' (retrieved 2026-08-23)
Entry last reviewed2026-08-23