Trust
Privacy and retention
Data classes, residency, deletion, and provider boundaries
Workspace governance selects the approved data region and retention periods for
source-derived data, findings/receipts, audit logs, and usage records. Shorter
repository policy cannot override a stricter workspace requirement.
Source is fetched for the immutable revision needed by the operation. Durable
records store normalized findings, redacted receipts, hashes, and provenance;
raw credentials are never part of those records. Third-party integrations
receive redacted summaries and links according to workspace policy.
BYOC and self-hosted customers own their database, object store, KMS keys,
secret manager, network, backup schedule, and deletion execution. Veridical
still operates release, licensing, support, and—depending on contract—identity
or model-provider processes, which remain in the subprocessor and data-flow
review.
Last modified on July 28, 2026
⌘I

