Overview
Azure Storage Accounts
data at rest is secured with soft-delete for 30 days
Azure OpenAI Deployments
prompts are filtered using Azure content filtering
prompts and responses are stored for 30 days and reviewed by Microsoft (Azure abuse monitoring)
SSO
SSO can be configured to connect to customer IDP using Entra, OIDC, SAML and other methods supported by Zitadel
Comparison with single tenant deployment model
On the multi tenant (SaaS) chat deployment model the most notable differences to the single tenant deployment model are
data at rest is mostly encrypted with Microsoft / platform managed encryption keys
data at rest is stored in shared storage accounts with other customers
data at rest is always stored in Switzerland (switzerland-north)
data is processed on the same backend service instances with other customers
users are logging in on the same zitadel instance with other customers