Security
Retention and deletion
Last updated · October 7, 2026
Durations are sized to your audit cycle. Governance evidence is kept for the contract term; operational logs are bounded.
Retention and deletion
| What | How long | Why |
|---|---|---|
| Your workspace data: identity, directory, HR, application rosters, catalogue, discoveries | Contract term, replaced at each sync | They reflect the current state of your estate. |
| Governance audit trail: requests, approvals, review decisions and snapshots, task history, agent state changes | Contract term | Evidence for your ISO 27001 and SOC 2 audits. |
| Activity logs, including IP address and user agent | Contract term | Audit evidence: who acted, from where, when. |
| Browser extension domain events | 180 days | Rolling, swept four times a day. |
| Browser extension prompt events | 90 days | Rolling, swept four times a day. |
| MCP tool call logs | 13 months | Covers a full SOC 2 Type II observation period and its reporting lag. |
| Access grid snapshots, working copies | 50 per workspace, 90 days | Pruned in the same transaction that writes a new one. The review evidence itself is kept for the contract term. |
| Directory profile photos | Removed when the person leaves your directory | Orphaned key, swept on the same schedule. |
| File exposure findings | Until the finding is resolved, then pruned at the next scan | A file that is no longer shared drops out of the list. |
| Integration secrets | Destroyed when the integration is disconnected | Immediately and irreversibly. |
| Edge access logs: IP, URL, user agent | Never exported, destroyed at each deployment | Written inside the web server container, with no volume attached. |
- You can delete an integration, a user or a set of findings from the application at any time.
- Disconnecting an integration destroys its stored secret immediately and irreversibly.
- At the end of a contract you choose export or deletion. Deletion in the application completes within 30 days of your request.
- Deletion in the application completes within 30 days. A backup cannot have one person removed from it, so backups expire on their own 90-day cycle and are never restored into production without re-applying the deletions requested since they were taken.
- Only records we are legally required to keep, such as invoicing, are retained beyond that. No governance data is.