Data Handling Matrix
What Aurora Keeps, and for How Long
| Data Category | Purpose | Retention and Deletion |
|---|---|---|
| Account, authentication, and profile data | Authentication, permissions, and account administration. | While the workspace is active; primary production deletion of authentication credentials, sessions, and profile settings is targeted within 14 days of paid-term end, subject to backups and legal retention. Account contact and billing-contact details follow the 7-year retention window in Billing and transaction data below. |
| Billing and transaction data | Subscription administration and payment processing (via Stripe). | Duration of the subscription plus 7 years for tax, accounting, and audit obligations. |
| Workspace customer content and evidence files | The policies, evidence, mappings, and exports a customer creates or uploads. | While the subscription is active; primary deletion targeted within 14 days of paid-term end, subject to backup and legal-retention windows. |
| Reviewer and Trust Center access data | Reviewer invitations, access status, and activity logs for customer-directed sharing. | 24 months. |
| AI prompt, output, and metadata logs | Operating Aurora Copilot and AI-assisted drafting features. | 90 days, unless the customer configures a longer window through an approved mechanism or a separate written agreement. |
| Training and acknowledgment records | Readiness records such as policy acknowledgements and training completions. | Duration of the subscription plus 12 months. |
| Support and account records | Support tickets, correspondence, and account-service history. | Duration of the subscription plus 36 months. |
| Usage, device, and audit-log data | Security monitoring, troubleshooting, and product analytics. | Varies by log type; security and audit-relevant logs may be retained longer. |
| Lead and demo request data | Following up on contact-form and walkthrough requests. | 24 months from the last interaction, then deletion or de-identification. |
Source: Privacy Policy §9 (Retention). When a self-service subscription ends, the customer is responsible for exporting data before the paid term ends.
Backups, Encryption, and How AI Features Handle Customer Data
TLS is enforced for the public site and application, with HTTP Strict Transport Security enabled (max-age one year, including subdomains).
Source: deploy/nginx.ssl.conf.template
The production application database is provisioned with storage encryption enabled, and evidence storage is encrypted with a dedicated per-tenant key, versioned, and blocked from public access. Aurora's Data Processing Addendum describes protection for data at rest as applied where appropriate to the environment.
Source: terraform/modules/tenant_stack/main.tf (storage_encrypted, per-tenant KMS key); DPA Schedule 2
Short-cycle backups roll on a 35-day cycle. Longer-cycle backups, disaster-recovery media, and archival snapshots may be retained and deleted on a different cycle than live production data.
Source: Privacy Policy §9; DPA Schedule 2 (Business continuity and backups)
When Borealis provides the AI model workflow, requests route to approved OpenAI-hosted or Anthropic-hosted APIs. Customers may instead configure a customer-supplied API key, in which case requests use that customer's own provider account.
Source: AI Notice; Privacy Policy §7
No. Unless a customer expressly opts in through a Borealis-approved mechanism, or a separate Borealis-signed agreement says otherwise, Borealis does not use Customer Data from Aurora Command workspaces to train generalized or shared AI models.
Source: Privacy Policy §7; AI Notice §2
No method of storage or transmission is completely secure, and Borealis cannot guarantee absolute security. Source: Privacy Policy §8.
Related Trust Resources
See the full subprocessor register, the security one-pager, or the assurance roadmap.
This page summarizes the Privacy Policy and Data Processing Addendum. Where those documents and this page differ, the signed agreement and DPA control.