Data retention

Last updated: October 5, 2026

This page records explicit retention windows for data classes that are not implicitly bounded by their parent record’s lifecycle. Anything not listed here lives until its parent organization, project, or user is deleted.

Retention table

Data classRetention periodWhy
LangGraph chat checkpoints (compliance-chat-…)Until user account deletion, organisation deletion, or 30 days — whichever comes firstBlobs hold verbatim user document excerpts and free-text chat turns (GDPR personal data)
LangGraph orchestrator checkpoints (run-…, qms-…)Until organisation deletion, or 30 days — whichever comes firstSame as above
LangGraph requirement-analyst checkpoints (req-…)30 daysRequirement IDs are global, so the thread cannot always be mapped back to a user or organisation at deletion time. This is the user-visible residual window described in Privacy Policy §8.
Personnel inventory (people, person_accounts)Until organisation deletionEmployment and tool-account join for offboarding evidence
Device inventory (assets)Until organisation deletion or connector disconnectManaged hardware roster from MDM (name, owner email, encryption, compliance)
Outbound questionnaire packsUntil organisation deletion or customer-admin deleteExtracted audit questions, cited drafts, reviews and internal notes. Source spreadsheets are not stored.
Interview voice recordings and transcripts30 days (INTERVIEW_AUDIO_RETENTION_DAYS)Voice answers and transcripts are personal data. cleanup-interview-audio deletes leftover recordings and transcript rows after the window. A successful transcription already deletes the audio object.
Public API request log90 daysUsage telemetry for the public API. prune-api-request-log hard-deletes rows older than 90 days.
Revoked or expired personal API keys30 days after revocation or expiryRevoked or expired keys stay visible for 30 days, then purge-user-api-keys hard-deletes them.
Control check runs90 days by default; paid tiers 396 days and 1095 daysConnector check history. prune-control-check-runs deletes aged rows. The newest run per organisation, check and integration, evidence-promoted runs, and runs referenced by current control state are kept.
Audit logsPer-row delete_at. Security actions default to 2190 days (6 years); other actions 395 days. Retention-excluded rows are scrubbed of personal data after 2190 days.Accountability. Rows are not anonymised solely because a user is deleted. purge-audit-logs deletes rows whose delete_at has passed, unless the row is retention-excluded; those rows have personal data scrubbed after 2190 days via iso56_scrub_audit_log_pii_batch.
Database backupsDaily physical snapshots, about 7 days retained. Point-in-time recovery is not enabled, so recovery is to the latest daily snapshot (up to 24 hours old).Disaster recovery for the production database. Point-in-time recovery is not enabled.
AI provider abuse-monitoring retentionOpenAI API and Azure OpenAI may retain inputs for abuse monitoring, typically up to 30 days, unless a zero-retention arrangement or exemption applies.Separate from Isodora’s own retention of chat, documents and transcripts.

LangGraph agent checkpoints

Retention: 30 days from the agent run that created the row. These tables hold serialised intermediate state for every agent run — compliance chat, compliance orchestrator, requirement analyst, QMS setup, document generator. The blobs include verbatim user document excerpts and free-text chat turns that constitute personal data under the GDPR.

  • On user account deletion, chat-session checkpoints under compliance-chat-{sessionId}- are purged.
  • On organisation deletion, checkpoints under compliance-chat-, run-{projectId}-, and qms-{orgId}- prefixes are purged. req-{requirementId}- rows are evicted only by the nightly cron.
  • A nightly retention job deletes anything older than the cutoff. The default 30-day window is configurable by Isodora (clamped to 1–365 days).

Configuration

  • The 30-day default can be shortened or extended by Isodora within 1–365 days.
  • Lowering it shortens the residual window for requirement-analyst threads.

Other classes

  • Evidence retention is currently bounded by organisation lifecycle.
  • Audit-log entries follow the per-row delete_at in the table above. They are not anonymised solely when a user is deleted, and they are separately time-bounded.
  • Remediation-task history is bounded by project lifecycle.