Board Pack
Retention and availability
How long each artefact is kept, which mechanism enforces each window, and why you should keep your own copy of the pack.
Different things are kept for different periods, and a different mechanism enforces each one.
| Artefact | Window | Enforced by |
|---|---|---|
| Raw evidence from your environment | 1 day by default | The workflow platform's own artifact expiry. It does not depend on anyone remembering |
| The board pack in the assessment workflow | 7 days by default | The same expiry |
| The assessment snapshot, used for comparison | 90 days by default | The same expiry. This is the comparison window |
| Your board pack in GovIntel storage | A retention window recorded against it | The service stops issuing links at expiry; removal is handled by the storage lifecycle policy |
Why the raw evidence expires fastest
It is the most sensitive artefact and the one nobody needs after the assessment. It contains resource identifiers, control results and cost telemetry, and it is internal only. A short window is the point.
Why the snapshot can be kept longest
It contains no customer identifiers. Control identifiers are the scanner's, resource identity is carried as fingerprints, and the account identifier is fingerprinted too. It names no resource and no account, which is what makes a longer retention defensible when the raw evidence expires in a day.
Keep your own copy
The portal shows the date your pack remains available until. Download it and keep it with your board records.
Your licence to the pack, under the Terms of Service, does not depend on GovIntel keeping a copy. Once the window closes, re-issuing means running a new assessment.
