Runfile
EU-WEST-1Northwood Bank
Search runs, controls, members, keys…⌘K
production4.8M / 12M eventsSPSahil Patel
Northwood BankGovernRetention

Retention

Retention floors come from the regulatory scope. You can extend, never reduce below the floor. Right-to-be-forgotten requests route through legal review.

Data classRetentionRegulatory floorBasisEdit
events10 years7 years (SOX) · 10 years (banking)banking record-retention
payloads90 days encrypted · then archived30 daysaccess pattern + DPA limit
token vault180 days default · 7 years for SSN/accountper-classDPO sign-off · v8
hash chain10 years (forever in evidence bundles)10 yearsaudit primary record
evidence bundles10 years10 years (banking)auditor-provided artefact
working papers10 years7 years (PCAOB)engagement deliverable
audit-of-audit log10 years10 yearsplatform transparency record
Right-to-be-forgotten

RTBF requests on audit data are exempt from blanket deletion. The workflow is mark for deletion → route to legal review → action only if approved. Every request, decision and outcome is itself an audit event.

0 pending2 actioned (last 90d)1 declined · legal
Deletion proof

When data is deleted under retention, the chain remains intact — the deletion itself is recorded as a chain event with a cryptographic proof. Auditors can verify what was deleted, by whom, when.