← All legal pages

Retention

Data Retention & Deletion

This page explains how long Enji Guard keeps different kinds of data, how to delete data or offboard, and what may remain afterwards. Specific deployments and signed agreements may set different retention terms.

Retention principles

We retain data only as long as needed to provide, secure, and support the Service, meet legal obligations, resolve disputes, and maintain auditability. Retention is purpose-based rather than a single fixed timer.

Product reports, findings, task and activity history, and operational logs are retained as product records and part of the product’s value, so they are not on a fixed time-based deletion schedule. Revoking access or unlinking a repository stops future use but does not automatically delete historical reports or history.

By data category

  • Account and product data — retained while your account and projects are active; handled on a deletion or offboarding request, subject to the backup, log, and legal or security exceptions described below.
  • GitHub installation data — tied to your installation; stops being used when you revoke or uninstall the GitHub App.
  • Execution workspaces — ephemeral; removed after each task, so the cloned repository code does not persist in the workspace.
  • Reports, findings, and audit history — retained as product records on a purpose-based basis.
  • Auto-pentest consent records — retained for auditability, including after a consent is no longer valid for future checks.
  • Auto-pentest reports — private to authorized users by default and retained as product records.
  • Logs and operational records — retained for reliability, security, and audit purposes.

Deletion controls

You can delete projects, repositories, and sites, disable schedules and jobs, and revoke the GitHub App; this stops future use, while retained records are handled as described below. For account deletion or offboarding, contact [email protected].

Deletion effects

After deletion, historical records may remain for a limited period in backups, logs, or audit records, and where required for legal or security purposes. Data already sent to third-party providers is subject to their own retention terms.