Data retention
Last updated: October 5, 2026
This page records explicit retention windows for data classes that are not implicitly bounded by their parent record’s lifecycle. Anything not listed here lives until its parent organization, project, or user is deleted.
Retention table
| Data class | Retention period | Why |
|---|---|---|
| LangGraph chat checkpoints (compliance-chat-…) | Until user account deletion, organisation deletion, or 30 days — whichever comes first | Blobs hold verbatim user document excerpts and free-text chat turns (GDPR personal data) |
| LangGraph orchestrator checkpoints (run-…, qms-…) | Until organisation deletion, or 30 days — whichever comes first | Same as above |
| LangGraph requirement-analyst checkpoints (req-…) | 30 days | Requirement IDs are global, so the thread cannot always be mapped back to a user or organisation at deletion time. This is the user-visible residual window described in Privacy Policy §8. |
| Personnel inventory (people, person_accounts) | Until organisation deletion | Employment and tool-account join for offboarding evidence |
| Device inventory (assets) | Until organisation deletion or connector disconnect | Managed hardware roster from MDM (name, owner email, encryption, compliance) |
| Outbound questionnaire packs | Until organisation deletion or customer-admin delete | Extracted audit questions, cited drafts, reviews and internal notes. Source spreadsheets are not stored. |
| Interview voice recordings and transcripts | 30 days (INTERVIEW_AUDIO_RETENTION_DAYS) | Voice answers and transcripts are personal data. cleanup-interview-audio deletes leftover recordings and transcript rows after the window. A successful transcription already deletes the audio object. |
| Public API request log | 90 days | Usage telemetry for the public API. prune-api-request-log hard-deletes rows older than 90 days. |
| Revoked or expired personal API keys | 30 days after revocation or expiry | Revoked or expired keys stay visible for 30 days, then purge-user-api-keys hard-deletes them. |
| Control check runs | 90 days by default; paid tiers 396 days and 1095 days | Connector check history. prune-control-check-runs deletes aged rows. The newest run per organisation, check and integration, evidence-promoted runs, and runs referenced by current control state are kept. |
| Audit logs | Per-row delete_at. Security actions default to 2190 days (6 years); other actions 395 days. Retention-excluded rows are scrubbed of personal data after 2190 days. | Accountability. Rows are not anonymised solely because a user is deleted. purge-audit-logs deletes rows whose delete_at has passed, unless the row is retention-excluded; those rows have personal data scrubbed after 2190 days via iso56_scrub_audit_log_pii_batch. |
| Database backups | Daily physical snapshots, about 7 days retained. Point-in-time recovery is not enabled, so recovery is to the latest daily snapshot (up to 24 hours old). | Disaster recovery for the production database. Point-in-time recovery is not enabled. |
| AI provider abuse-monitoring retention | OpenAI API and Azure OpenAI may retain inputs for abuse monitoring, typically up to 30 days, unless a zero-retention arrangement or exemption applies. | Separate from Isodora’s own retention of chat, documents and transcripts. |
LangGraph agent checkpoints
Retention: 30 days from the agent run that created the row. These tables hold serialised intermediate state for every agent run — compliance chat, compliance orchestrator, requirement analyst, QMS setup, document generator. The blobs include verbatim user document excerpts and free-text chat turns that constitute personal data under the GDPR.
- On user account deletion, chat-session checkpoints under compliance-chat-{sessionId}- are purged.
- On organisation deletion, checkpoints under compliance-chat-, run-{projectId}-, and qms-{orgId}- prefixes are purged. req-{requirementId}- rows are evicted only by the nightly cron.
- A nightly retention job deletes anything older than the cutoff. The default 30-day window is configurable by Isodora (clamped to 1–365 days).
Configuration
- The 30-day default can be shortened or extended by Isodora within 1–365 days.
- Lowering it shortens the residual window for requirement-analyst threads.
Other classes
- Evidence retention is currently bounded by organisation lifecycle.
- Audit-log entries follow the per-row delete_at in the table above. They are not anonymised solely when a user is deleted, and they are separately time-bounded.
- Remediation-task history is bounded by project lifecycle.