Standard retention preserves the review record
Organizations default to 90 days of screening evidence. An authorized administrator can configure a period from 1 to 3,650 days. The retained record includes the original outcome and versions; analyst decisions are appended while the evidence remains available.
An expiry is meaningful: maintenance clears subject, request, result, and associated case-note content. Minimal tombstone and usage information can remain for consistency. Do not promise your customers an indefinite audit archive when the configured policy deletes necessary records.
Minimal mode reduces what the server keeps
A one-time screening can set retention to minimal. The submitted subject and request are not retained; submitted values in persisted match explanations are redacted. A reduced outcome and source facts remain for 24 hours. The immediate response may still contain submitted values, so your own storage and logs need their own controls.
The retained request digest is for duplicate detection. It is not proof that data is anonymous and is not a tamper-proof record. Once necessary inputs are gone, full historical replay is unavailable even if a source snapshot still exists.
Monitoring and backups need separate treatment
Active monitoring retains its subject until stopped and deleted. Customer uploads expire after 24 hours; webhook delivery history after 90 days; audit events after 365 days. Failed private-object deletion is retried. Original source versions remain subject to approved source-retention rules and retained evidence references.
Provider backups follow a separate configured expiry window. Deleting a current row is not a promise of immediate deletion from every backup. Confirm the backup window, source rights, legal holds, and restoration procedure with the operator’s approved privacy policy.
KEEP BUILDING