Perplexity is quick to adopt because anyone can open it in a browser and start asking questions. That is also the risk. A team member pastes a client brief, a contract excerpt or a customer list into a personal account, and company data is now governed by consumer terms nobody on your side reviewed. Keeping data safe in Perplexity is mostly about three things: being on the right plan, switching on the controls that plan gives you, and agreeing on what never goes in.
Start with the plan, not the prompt
Perplexity's business offering, Enterprise, is documented separately from its personal plans. According to Perplexity's enterprise security material, enterprise data is not used to train or fine-tune its models, and the company states that it holds agreements with its third-party model providers that keep them from training on your data either. It also describes itself as SOC 2 Type II attested. Those are the claims to verify against the current terms and trust documentation before you rely on them, and the reason a personal login is the wrong place for company work: the protections above belong to the organization account, not to the person.
Get everyone into the organization account
The first control is simply membership. Organization admins can set up single sign-on and make it mandatory, using an identity provider such as Okta, Azure AD or Google Workspace. Per Perplexity's help center, organizations with 50 or more seats can add SCIM provisioning, which automates adding and removing users. The practical payoff is offboarding: when someone leaves and their directory account is disabled, their access to company threads and files goes with it.
Set retention and incognito at the organization level
Enterprise admins get a dedicated data and privacy section in organization settings. It covers data retention, including an option to enforce incognito mode, along with model and provider settings and audit log settings. Perplexity's documentation ties custom retention windows to larger organizations and higher tiers, so check what your plan actually includes. If your records policy says client material should not sit in a vendor system indefinitely, this is where you set a shorter window, or enforce incognito, rather than trusting every user to remember.
Decide which models your team can use
Perplexity lets admins choose which large language models the organization can use. Treat that as a security setting and not a preference menu. Each model provider is another party in the chain, so limit the list to the providers your security or compliance review has approved, and revisit it when new ones are added.
Turn on audit logs and actually look at them
Enterprise plans offer audit logs covering things like login attempts, data changes and configuration changes. A log nobody reads is only a record after the fact, so give it an owner and a cadence: a monthly skim for unfamiliar sign-ins and settings that changed without a ticket is enough to catch most drift.
Write down what never goes in
Controls reduce exposure; they do not replace judgment. A one-page rule set does more than any setting. Keep credentials, API keys and passwords out of prompts entirely. Keep regulated or contractually restricted material out unless your agreement and your client's terms explicitly allow it. Strip names and identifiers from anything you paste when the question does not need them. And treat what comes back as a research draft: answers cite web sources, and a person should open the source before a claim reaches a client or a published page.
A short checklist
Confirm everyone works in the organization account. Require SSO. Enable SCIM if your seat count allows it. Set retention or enforce incognito. Restrict models to the approved list. Assign an owner to the audit log. Publish the never-paste list and review it twice a year. If a vendor claim matters to a contract or a client commitment, read the current terms yourself, because plans and policies change.