Data Retention & Deletion

Last updated

What is kept, for how long, and what deleting it actually removes. The headline: this application deletes nothing automatically. Data stays until someone removes it, and the tools to remove it are described below.
Written against the code, not from a template. Every behaviour described here is implemented in this application, and the limitations are listed as plainly as the capabilities. If you find a statement on this page that the software does not match, that is a bug — please tell us.
On this page

There is no automatic retention

Most retention policies open by stating a period. This deployment has not set one, so nothing is deleted on a schedule: scans, findings, audit entries and agent telemetry accumulate until an operator or a user removes them.

The enforcement exists — it is off. Setting SCAN_RETENTION_DAYS turns on an hourly sweep that deletes scan history past that age. It is deliberately opt-in: a default would have started destroying history on upgrade, on the strength of a number nobody chose, with no undo.

Until you set it, retention on your deployment is whatever you enforce yourself. If you are operating this for other people and telling them you apply a retention period, that statement will not be true until you configure one.

What is stored, and for how long

DataKept untilNotes
Scans and findingsDeleted by youIncludes raw scan evidence — response headers, discovered paths, masked secret matches
Finding triage decisionsDeleted with the assetStatus, owner and justification, per user
AssetsDeleted by youDeleting an asset removes its scans, findings and triage history
Audit logNever deletedDeliberately — an audit log you can delete is not an audit log. Entries are redacted rather than removed when a user is erased
Agent sessions and eventsDeleted with your accountArguments are stored as a hash, never as their contents
Sessions and API keysUntil expiry or revocationSessions expire; API keys last until revoked
AccountUntil you erase itSee below for what erasure does and does not remove

How to delete things

Deletion is real and immediate — rows are removed, not flagged.

  • A single scan — removes that scan and its findings. Triage history for the asset survives, since it belongs to the asset rather than to one scan.
  • An asset — removes the asset, every scan of it, every finding, and the triage history. Requires confirming the hostname, because it is not recoverable.
  • Your account — removes your sessions, API keys, agent telemetry and triage decisions, and every scan you triggered. Assets you created that nobody else has scanned are deleted; assets others have also scanned are kept but disassociated from you.

What deletion does not remove

Stated plainly, because each of these surprises somebody:

  • Audit log entries survive account erasure. They are redacted — your email is replaced with a marker and the user reference removed — but the record that an action happened remains. An audit log that disappears when the person responsible deletes their account provides no accountability at all.
  • Shared assets survive. If a colleague has also scanned an asset you created, deleting your account does not delete their scan history.
  • Database free pages may retain deleted content until reclaimed. Deleting a row marks its space reusable rather than overwriting it. Run VACUUM if you need the bytes genuinely gone.
  • Backups and snapshots are outside this application entirely. Whatever deletion removes here, it cannot reach a copy your infrastructure made yesterday.

Exporting your data

A complete JSON export of everything associated with your account is available from your account page: assets, scans, findings, triage decisions, agent sessions, API key metadata (never the keys themselves), and your audit entries. It is generated on request from live data rather than a periodic dump, so it is current at the moment you ask for it.

Backups and copies

This application takes no backups. Whatever backup regime exists is one your infrastructure provides, and its retention is governed by your configuration, not by anything here. If you are making a retention commitment to anyone, your backups are the part most likely to break it.

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

Personal addresses (gmail, outlook, and similar) are not accepted.

+91

0 / 4000