Dashboard
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →

Q20IntermediateScenario

Midway through the project, the customer's security team blocks sending any data to external LLM APIs. What are your options?

30-second answerSay your answer out loud first, then reveal.

Options matrix

OptionAddressesTrade-offs
Enterprise API with zero data retention + DPATraining and retention concernsData still leaves their network
Models via the customer's own cloud account (managed model services in-region)Residency, network boundary, existing vendor agreementsModel availability varies by region
Self-hosted open-weight models in their VPC / on-premFull control, air-gap possibleGPU cost, ops burden, possibly lower quality
PII redaction / pseudonymisation before the APISensitive fields never leaveDetection must be reliable; some context lost
Hybrid: sensitive tasks local, others APIBalanceComplexity

How to run it

  1. Meet security early: bring a clear data-flow diagram, data classification and threat model.
  2. Ask what would be acceptable. Security teams often have approved patterns.
  3. Re-run the eval set on candidate options (e.g. a self-hosted model) to quantify the quality impact.
  4. Update the timeline and plan transparently; tell the business sponsor about any delay early.
Interview signal: treating security as a partner with legitimate concerns, not an obstacle, and having concrete architectural alternatives.

Every expert started right here.