Skip to content

Documentation

Retention Policy

Standard retention, export, and deletion practices for hosted customer data.

RuntraceLast updated July 24, 2026

Scope

This policy describes the standard retention, export, and deletion practices for hosted Runtrace Business. An Enterprise order form may define different periods or a private deployment boundary.

Runtrace does not retain source code, file contents, secret values, shell history, screenshots, clipboard contents, or arbitrary command output because the agent does not upload those data categories.

Standard retention

Active organization operational data

Devices, current telemetry snapshots, findings, vulnerability groups, finding workflow state, allowlists, remote scan requests, pilot and lifecycle acceptance receipts, policies, reports, users, members, and billing state.

  • Retention: Kept while the organization is active so admins can track remediation, trends, audit history, and billing status.
  • Deletion: Removed by guarded organization deletion after billing is canceled or the account is free/local; a minimal deletion receipt remains.
  • Exportable: Yes

Audit and workflow evidence

Billing changes, remote scan queue/claim/fail/cancel events, report generation/delivery, package-bound pilot and lifecycle acceptance records, finding workflow notes, allowlist changes, enrollment-token changes, and deletion receipts.

  • Retention: Kept with the active organization and included in export/audit CSV so security and billing actions remain reviewable.
  • Deletion: Tenant audit events are removed by organization deletion; the deletion receipt keeps the deletion actor, time, reason, billing state, and removed-record counts.
  • Exportable: Yes

Billing and subscription metadata

Plan, status, seat limit, billing period, Revolut customer/subscription identifiers, cancellation requester/reason/time, webhook event IDs, and signup request metadata.

  • Retention: Kept while needed to operate checkout, subscriptions, support, accounting, cancellation, and fraud/error investigation.
  • Deletion: Operational billing state and organization-scoped webhooks are removed by organization deletion when billing permits deletion; deletion receipt remains for legal/accounting evidence.
  • Exportable: Yes

Admin sessions and access records

Server-side session IDs, OIDC subject/email/name/roles, allowed organization claims, membership records, and session expiry timestamps.

  • Retention: Sessions expire automatically by timestamp; user/member records are updated on login and retained while organization access exists.
  • Deletion: Organization deletion removes scoped sessions, memberships, and users that no longer belong to another organization.
  • Exportable: Yes

Raw secrets and source contents

Secret values, private-key contents, API token values, source files, document contents, screenshots, clipboard contents, shell history, terminal output, and arbitrary command output.

  • Retention: Not uploaded by design; telemetry ingestion rejects obvious raw private-key and API-token patterns before storing snapshots.
  • Deletion: No product retention applies because these contents should not enter the fleet store.
  • Exportable: No

Customer controls

  • Authorized administrators can export organization data before account deletion.
  • Devices can be deactivated immediately to stop authentication and release an active seat.
  • Audit history and reports can be downloaded during the subscription.
  • Account deletion requires an authorized administrator and confirmation of the organization.

Backups and deletion

Deletion removes active customer records from the application. Backup copies expire through the normal backup-retention cycle and are used only for disaster recovery. Runtrace may retain minimal billing, legal, security, and deletion records where required by law or necessary to establish, exercise, or defend legal claims.