Data Retention and Deletion
This page explains how long Controlio keeps your monitoring data, when it deletes it automatically, and how it deletes it at your request.
Standard retention: 1 year
The standard history retention period is 366 days (1 year). The database containers that hold history data (configSnapshots, goldenAudit, driftFindings, goldenProposals, vipLiveEvents, securityEvents) have a time-to-live (TTL) set; standard history older than one year is deleted automatically. This avoids keeping data indefinitely for no reason.
These 366 days are counted per record, from the moment each record is written (Cosmos TTL, from the record's last update). There is no single counter that starts after a "lock"; each history/event record is removed 366 days after its own write date.
Current-state data has no expiry (no TTL): your approved configuration (golden / lock), the monitored scope (baseline), your monitored VIP list and tenant settings are not subject to a time-to-live — they are kept while monitoring is active and removed only through the deletion paths below. The 366-day period applies only to history and event records. This is the same whether your tenant is Monitored (unlocked) or Locked.
A longer retention period, such as two years, can be offered as a separate package. If you need it, talk to your account manager.
After the license ends
- When your trial or paid license expires, a 30-day grace period starts.
- If you renew within 30 days, your history is preserved.
- If you do not renew, your tenant's CCM / TrueState / VIP Guard history data is deleted automatically.
This deletion is tenant-scoped and resolved only by your immutable tenant id; no other tenant's data is touched. It is safe to run again. When deletion completes, a deletion proof that contains no personal data (tenant id, timestamp and deleted-row counts) is kept in a separate, never-purged record.
Early deletion request
You can request deletion of all your monitoring data without waiting for the standard period to end. This does not run instantly and irreversibly on a single click; it goes through a strong confirmation step that clearly explains the scope and outcome. The request is initiated by your authorized tenant administrator and leaves an auditable record.
The deletion request process and its verification are defined in our service team's operations runbook.
The "Delete My Assessment Data" button on the Account page
The rules above concern your continuous monitoring (CCM / TrueState / VIP Guard) data. Separately, the "Delete My Assessment Data" button on your Account page deletes the data from your classic security assessment (scan). It goes through a two-step confirmation where you type your company name, and it cannot be undone.
This button deletes:
- All scan results and history
- Uploaded script outputs
- Subscription / license distribution history
- Login traces and user preferences
If continuous monitoring is active, confirming this action also stops continuous monitoring. This does not happen silently: a mandatory notification is sent to your administrators and a permanent audit record is kept. If monitoring cannot be stopped for any reason, nothing is deleted and you are asked to try again. If you only want to stop monitoring without deleting data, use the deactivate action on the monitoring screen.
This button does not delete your monitoring data (TrueState, VIP Guard records). This is by design: deleting monitoring data (golden / lock, baseline, VIP, audit trail) is not something a single administrator can do with one click. If you want your monitoring data deleted, open a support request — your request goes through the controlled early deletion process with stronger verification. If you do not open a request, monitoring data is deleted automatically under the retention rules above (1 year / approximately 30 days after your license ends). Your license and company record, and the audit record of the deletion event (which contains no personal data), are kept.
Records kept for legal reasons
The retention and deletion rules above concern your monitoring/security data. Records that must be kept for legal reasons, such as invoices and contracts, are held separately and only for the period the law requires.