> ## Documentation Index
> Fetch the complete documentation index at: https://veridical-dev.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy and retention

> Data classes, residency, deletion, and provider boundaries

Workspace governance selects the approved data region and retention periods for
source-derived data, findings/receipts, audit logs, and usage records. Shorter
repository policy cannot override a stricter workspace requirement.

Source is fetched for the immutable revision needed by the operation. Durable
records store normalized findings, redacted receipts, hashes, and provenance;
raw credentials are never part of those records. Third-party integrations
receive redacted summaries and links according to workspace policy.

BYOC and self-hosted customers own their database, object store, KMS keys,
secret manager, network, backup schedule, and deletion execution. Veridical
still operates release, licensing, support, and—depending on contract—identity
or model-provider processes, which remain in the subprocessor and data-flow
review.
