Blog · AI

How to Keep Your Company Data Safe in DeepSeek

September 2026 · Sourced from DeepSeek's published privacy policy and public security reporting

DeepSeek is free, fast and easy to try, which is exactly why it ends up on work laptops before anyone has reviewed it. The question for a business is not whether the model is any good. It is where your data goes once someone pastes it in. DeepSeek is really two different things: a hosted app and API run by the company, and a set of open-weight models anyone can download and run themselves. The risks, and the fixes, are different for each.

What the hosted app collects, and where it goes

DeepSeek's privacy policy says it collects what you type, including prompts, uploaded files and chat history, along with account details, device and network information, and keystroke patterns. Reviews of the policy also note that this data is stored on servers in the People's Republic of China. Whatever a company's view of that jurisdiction, it is a data-residency and legal-access question your contracts, client agreements and any regulated-data obligations may already answer. If they do, the answer for the hosted app is usually no.

It has already had a security incident

In January 2025, researchers at Wiz reported finding a publicly reachable DeepSeek database that exposed more than a million lines of log data, including chat history, secret keys and backend details. DeepSeek secured it after being notified. One incident does not define a vendor, but it is a fair reason to treat anything typed into the hosted service as data you should assume you cannot pull back.

Others have already drawn a line

Several governments and agencies have restricted DeepSeek on official devices, citing privacy and national security concerns. Reporting has named Italy, Australia, Taiwan and the Czech Republic, along with US federal bodies such as the Commerce Department and the Navy and a number of US states. You do not need to follow their conclusions, but if you sell to government or regulated customers, expect the question to come up in a security review.

Keep the hosted app off company work

The simplest control is the blunt one. Do not use the DeepSeek app or its hosted API for anything that includes client information, source code, credentials, contracts, financials or personal data. Block or monitor it on managed devices if your tooling allows, and say so in your acceptable-use policy so the rule is written down and not just assumed. Personal accounts on a work browser are the usual gap, so the policy has to cover them.

Self-hosting is a different risk profile

DeepSeek has released open-weight models that can run on your own infrastructure or through a cloud provider you already trust. In that setup, prompts go to a system you control, not to DeepSeek's servers, which removes the main data-residency concern. It does not remove the rest. You take on patching, access control and logging, and you should have security review the model files and serving software as you would any other third-party code. Self-hosting is a legitimate option for teams that need it and have the staff to run it, and a poor one for a team that just wants a free chatbot.

Write down what never goes in

Whatever you decide about DeepSeek, the same rule set applies to every AI tool. Keep credentials, API keys and passwords out of prompts. Keep regulated or contractually restricted material out unless your agreements explicitly allow it. Strip names and identifiers from anything you paste when the question does not need them. And treat answers as a draft: a person checks anything that reaches a client or a published page.

A short checklist

Decide whether the hosted DeepSeek app is approved, and record the decision. If it is not, block it on managed devices and cover personal accounts in policy. If you want the model, evaluate a self-hosted or cloud-provider deployment with your security team. Publish the never-paste list and review it twice a year. If a vendor claim matters to a contract or a client commitment, read the current policy yourself, because terms and jurisdictions change.

Not sure which AI tools your team is already using, or what data is going into them? Our audit maps that against how your team actually works.

Book an audit

← All posts