Security & Privacy

Data retention schedule

What is kept, for how long, and which mechanism enforces each window, including the records for which no automatic deletion exists.

Currentengine 9.0.0Verified 2026-08-30

Different things are kept for different periods, and a different mechanism enforces each. So that you can judge it, here is what each actually is.

HeldWindowEnforced by
Raw evidence from your environment1 day by defaultThe assessment platform's own artifact expiry. It does not depend on anyone remembering
Board pack in the assessment workflow7 days by defaultThe same expiry
Assessment snapshot90 days by defaultThe same expiry. This is also the comparison window
Board pack in GovIntel storageA retention window recorded against the packThe service stops issuing links at expiry; removal is handled by the storage lifecycle policy
Enquiry and engagement records, including the onboarding audit trailFor as long as there is a relationship, and afterwards as needed for legal, accounting and tax obligationsNothing automatic
Database backupsRotated on a short cycle, currently fourteen daysBackup rotation

The row that deserves emphasis

Nothing in the product deletes enquiry and engagement records automatically. There is no scheduled purge and no expiry rule on them.

That is stated plainly because the alternative — a numeric retention promise that nothing enforces — would be a policy claim with no mechanism behind it. If you want those records removed, ask, and they will be.

Why the evidence expires fastest

It is the most sensitive artefact and the one nobody needs after the assessment.

Why the snapshot can be kept longest

It carries no customer identifiers. That is what makes a longer window defensible when the raw evidence expires in a day.

Your own copy

Download your pack and keep it with your board records. Your licence to it does not depend on GovIntel retaining a copy.