1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →
Midway through the project, the customer's security team blocks sending any data to external LLM APIs. What are your options?
30-second answerSay your answer out loud first, then reveal.
Options matrix
| Option | Addresses | Trade-offs |
|---|---|---|
| Enterprise API with zero data retention + DPA | Training and retention concerns | Data still leaves their network |
| Models via the customer's own cloud account (managed model services in-region) | Residency, network boundary, existing vendor agreements | Model availability varies by region |
| Self-hosted open-weight models in their VPC / on-prem | Full control, air-gap possible | GPU cost, ops burden, possibly lower quality |
| PII redaction / pseudonymisation before the API | Sensitive fields never leave | Detection must be reliable; some context lost |
| Hybrid: sensitive tasks local, others API | Balance | Complexity |
How to run it
- Meet security early: bring a clear data-flow diagram, data classification and threat model.
- Ask what would be acceptable. Security teams often have approved patterns.
- Re-run the eval set on candidate options (e.g. a self-hosted model) to quantify the quality impact.
- Update the timeline and plan transparently; tell the business sponsor about any delay early.
Interview signal: treating security as a partner with legitimate concerns, not an obstacle, and having concrete architectural alternatives.
Related
Every expert started right here.