Trust & transparency
Retention
SentriRail trust center document. Automated technical assessment — not a legal certification.
| Data | Retention |
|---|---|
| Accounts / sessions | Until account deletion |
| Scans | Plan history quota (14 / 90 / 365 days) |
| Network metadata | Redacted, tied to the scan run |
| Screenshots | CMP opt-in, 14 days, signed URL |
| Evidence | Hash chain + bundle while the site exists |
| Application logs | Redacted, Docker rotation |
| Emails | Local outbox then Resend; no transactional pixel |
| Backups | BACKUP_RETENTION_DAYS (default 14) |
| Runtime observations | Aggregated hosts, flag off |
Detail: /security#retention.
SentriRail is a drafting aid. It is not legal advice. You are solely responsible for whether generated documents fit your situation. When in doubt, consult a privacy lawyer.