Skip to content
Foxx Cyberfoxxcyber/docs

Data Retention & Deletion

How long the platform keeps each category of data, and how deletion works.

This page describes retention and deletion for the hosted Bedrock CMMC platform. (Bedrock C3PAO runs air-gapped inside the operator's own boundary — Foxx Cyber holds no C3PAO assessment data, so there is nothing for us to retain or delete. See Where CUI Lives.)

Last reviewed: 2026-07-29.

Retention by data category

DataRetainedNotes
Account & organization dataLife of the subscriptionUsers, roles, organization profile, settings
Compliance records (SPD)Life of the subscriptionControl statuses, POA&Ms, asset records, SSP content — exportable by you at any time
Uploaded evidence filesUntil you delete them, or the subscription endsDeleting an evidence record can also remove the underlying stored object, freeing your storage quota
Generated exports & downloads90 daysExport packages and generated downloads expire automatically
Database backups35-day rolling windowEncrypted automated backups; deleted data ages out of all backups within this window
Operational & security logs365 daysApplication, network, and security-service logs
Audit-log archive7 yearsTamper-evident audit records move to cold storage after 1 year and are retained 7 years total, supporting AU-11-style retention requirements
Evaluation sandboxesTime-limitedSandbox organizations are purged after their evaluation window expires, unless converted to a paid subscription (conversion carries the data over)

How deletion works

  1. Self-service — you can delete evidence records (optionally including the stored file) and other content through the application at any time.
  2. At offboarding — when a subscription ends, export your data first (see Exporting Package Data), then request deletion in writing through your Foxx Cyber point of contact or a support ticket. We verify the request, remove the organization's data from the production system, and the remaining copies age out of the encrypted backup window within 35 days.

Audit records are the deliberate exception: entries recording that an action happened (who, what, when) are retained for the full audit period even after the underlying content is deleted — that's what makes the audit trail trustworthy. Audit entries reference content; they don't contain uploaded file contents.

Last updated July 29, 2026