Security and data

Zero Data Retention

When Zero Data Retention (ZDR) is on, Composio does not store the payloads of covered calls. It runs each covered tool call and Proxy Execute request and returns the result without writing the request arguments, response data, or error text to its execution logs. The log for each call keeps metadata only, such as IDs, the tool, timing, and the HTTP status code.

ZDR is available on paid plans for a usage-based price and included on Enterprise. An organization admin turns it on in Organization Settings > Billing > Add-ons.

How ZDR works

For each covered call, Composio writes a log that holds metadata only:

DataFields
StoredIDs for the log, project, connected account, auth config, API key, session, sandbox, and request. The user ID you pass. The toolkit, tool, and tool version. The SDK source, runtime, and framework. Timing, the HTTP status code, and whether the call errored.
Not storedRequest arguments, response data, and error text.

Composio stores the user ID you pass, so use opaque IDs, such as a database key, rather than emails or names.

Scope

ZDR applies per project. It covers requests that use a ZDR project's API key, session, or MCP URL.

On the Enterprise plan, new projects start with ZDR on, whether you create them in the dashboard or through the API. On other paid plans, new projects start with ZDR off, even when ZDR is on for all projects. Turn it on for each new project in the dashboard.

Projects without ZDR keep storing payloads. Send requests that need ZDR only to projects that have it on.

What ZDR covers

In a ZDR project, Composio does not store payloads for:

  • Tool calls, whether you execute a tool directly or through a session.
  • Proxy Execute requests.

ZDR covers calls through Composio Managed apps only on the Enterprise plan.

With ZDR on, the log keeps the tool, status, and latency. The request and response are not stored.

What ZDR does not cover

ZDR does not cover the following, even in a ZDR project. For how long Composio keeps logs, files, and sandbox data, see Data retention.

FeatureDetailsWhat to do
Composio Managed apps, except on the Enterprise planAuth configs that use Composio's own OAuth app.Use your own OAuth app for toolkits that need ZDR. Existing users reconnect through the new auth config. You can also contact sales about Enterprise.
Instant ToolsComposio does not store their payloads, but the third-party provider behind each hosted account may keep data under its own policy.Set instant=False in Python or instant: false in TypeScript when you create Sessions that handle data that needs ZDR.
TriggersWith ZDR on, trigger logs leave out event payloads, but Composio still stores the events to process and deliver them.Do not use triggers for data that needs ZDR.
SandboxThe sandbox includes the Workbench and remote Bash. Sessions also offload large responses to it. Sessions turn on the sandbox by default.Disable the sandbox when you create sessions.
FilesComposio stages files that tools upload or download, including Proxy Execute binary responses, and cleans them up after 24 hours.Do not use tools that upload or download files for data that needs ZDR.
Requests with the x-debug: true headerComposio archives these requests for debugging.Do not send this header from ZDR projects.
Tool search in sessionsComposio can cache search queries to improve results.Keep sensitive data out of search queries, or use the direct tools preset to turn off tool search.
Third partiesThe destination apps you connect, your model provider, external MCP servers, and your own logs keep their own data policies.Review each provider's data policy, and set retention for your own logs.

Disable the sandbox in sessions

Turn off the sandbox when you create a session:

from composio import Composio

composio = Composio()

session = composio.sessions.create(
    user_id="user_123",
    sandbox={"enable": False},
)

See Disabling the sandbox for what changes in the session.

Always stored

Composio stores audit logs and telemetry on every plan, and ZDR does not change them:

  • Audit logs record who did what and when, including the metadata row for each tool call.
  • Telemetry is the metrics, traces, application logs, error reports, and usage metering that Composio uses to run and bill the service. Telemetry can include error messages returned by providers.

Existing data

ZDR applies only to new calls. Logs written before you turned it on keep their payloads for up to one year under the standard retention policy. To delete them sooner, email support@composio.dev with the project ID. If you turn ZDR off, new calls store payloads again.

Turn ZDR on or off

Only organization admins can turn ZDR on or off. Other members can see its status but cannot change it.

  1. In the dashboard, open Organization Settings > Billing.
  2. Under Add-ons, turn on Zero Data Retention.
  3. Review the price and what ZDR does not cover, then confirm. ZDR turns on for every current project.

To turn ZDR on or off for one project, open Project Settings > General and use the Zero Data Retention setting. To turn it off for every project, turn off Zero Data Retention in Billing.

Hobby plan

ZDR is not available on the Hobby plan. Projects that already had Don't store data on keep ZDR on, and an admin can turn it off. Turning it back on requires a paid plan.

Projects that used Don't store data

ZDR replaces the Don't store data option under Log storage. Projects that had it on now have ZDR on, and the rest have it off.