AI Configuration Security and Data Privacy

Summary

To help you get the most value from AI Configurations in the PIM, we strongly recommend following the guides below:

 

Overview

Akeneo is committed to protecting your data privacy and maintaining the highest standards of security in every AI-powered feature.

All product information processed by Akeneo’s AI features  including content generation, translation, and rephrasing  is handled securely using OpenAI Enterprise, a fully isolated, enterprise-grade infrastructure designed for business use.

Your data is never used to train AI models, never shared with third parties, and never stored after processing.

This page explains how your data flows through Akeneo’s AI systems, what information is shared with our AI provider, and how you can safely use these features while complying with internal governance policies.

 

How Data is Processed

When you use an AI feature (such as Generate with AI, Translate, or Prompt Optimizer), Akeneo temporarily sends specific product data and the related prompt to OpenAI’s Enterprise API for processing.

Once the AI model returns a response, the data is immediately discarded from the AI provider’s systems and stored only within Akeneo (if you choose to save the result).

Key Principles

  • All data is transmitted over encrypted channels (HTTPS / TLS 1.2+).
  • OpenAI Enterprise maintains no data retention  meaning nothing is logged or reused for model training.
  • Akeneo’s AI integration is designed for stateless processing  each generation is a separate, temporary request.
  • Only the minimum required information is sent to generate the result.
     

Information Shared with the AI Provider

The data shared depends on the action you’re performing. Below is a summary of what Akeneo sends for each type of AI operation.

Use Case Data Shared Description
Content Generation Product name, selected attribute values, locale, prompt Required to generate new text or values from your PIM data.
Translation Source locale, target locale, value to translate, prompt Used to produce accurate translations following your tone of voice.
Rephrasing Value to rephrase, type of rephrasing Used for text cleanup or tone adjustments.
Prompt Analysis (Optimizer) The prompt text itself, and all AI configuration settings Used to evaluate clarity, tone, and attribute relevance based on C.R.A.F.T.+R.

Akeneo does not send any customer-identifying metadata, such as company names, user details, or PIM environment information. If you choose to include brand names or sensitive data directly in a prompt, it will be visible to the AI model temporarily during that request only.

AI Models Used

Akeneo uses only models hosted in OpenAI’s Enterprise environment, which provides strict separation from consumer APIs.

Use Case Model Used Description
Text generation GPT-4.1-mini Fast, accurate, optimized for enrichment and content creation.
Translation GPT-4.1-mini Specialized for multilingual consistency.
Rephrasing GPT-4.1-mini Ensures clear and tone-consistent output.
Image analysis GPT-4.1-mini Used for basic asset interpretation.
Controlled rollout GPT-5, GPT-5 nano, GPT-5 mini Available to select customers by requesting access. 
Please reach out to your CSM for access or more information.

 

Additional Security Measures

To ensure the integrity and confidentiality of your data, Akeneo implements the following controls:

  • End-to-end encryption for all data transfers
  • Zero data retention within OpenAI Enterprise
  • No third-party integrations outside the secured environment
  • Access control by user role and permissions
  • Regular security audits across all Akeneo systems

In addition, AI-related actions (for example, prompt analysis or generation) are logged internally for observability, without exposing sensitive content.
 

Customer Responsibilities and Recommendations

While Akeneo protects your data at every stage, responsible usage also depends on your internal governance. To help maintain compliance and control, we recommend the following best practices:

  1. Avoid including confidential data in prompts.
    Don’t manually add sensitive internal information, such as financial figures, employee data, or proprietary source material, inside your prompts.
  2. Review generated content before publishing.
    Use Workflows or internal approval processes to validate content accuracy, tone, and compliance before release.
  3. Control user permissions.
    Ensure only trusted users have access to AI features or the ability to create configurations.
  4. Follow internal data protection policies.
    Align Akeneo usage with your company’s GDPR, SOC2, or other compliance frameworks.
  5. Document your configurations.
    Keep a record of prompts, their purposes, and associated attributes for transparency and audits.

 

Frequently Asked Questions

Is my data used to train AI models?
No. Akeneo uses OpenAI Enterprise, which never stores or trains on your data.

Can I request deletion of all AI processing data?
There is no need  OpenAI Enterprise retains no data. Akeneo stores only the resulting values you choose to save.

Can administrators restrict AI access?
Yes. Role-based permissions can limit which users can view, create, or execute AI Configurations.

Does Akeneo review customer prompts or generated content?
No. All AI processing is automated and isolated. Akeneo teams do not view or access customer data or prompts.
 

Summary

Akeneo’s AI features are designed to combine innovation with enterprise-grade security.
Your data remains within a controlled, encrypted, and compliant environment from start to finish.
By following the recommended governance practices above, you can confidently use AI enrichment while maintaining full compliance with your internal security standards.
 

Next Steps

Now that you understand how your data is secured, you can explore:

Limits and Considerations to learn how to optimize performance safely.

Frequently Asked Questions for quick answers to common data and usage queries.