Skip to content
Data handling

Data Handling Matrix

A structured summary of how Aurora Command classifies, retains, backs up, and secures each category of Customer Data, and how AI-assisted features fit into that picture. Every row traces back to the Privacy Policy, the Data Processing Addendum, or a specific configuration file.

Retention and deletion

What Aurora Keeps, and for How Long

Baseline windows published in the Privacy Policy. Law, contract, legal hold, or an active security investigation can extend these windows.

Aurora Command data-handling matrix
Data CategoryPurposeRetention and Deletion
Account, authentication, and profile dataAuthentication, permissions, and account administration.While the workspace is active; primary production deletion of authentication credentials, sessions, and profile settings is targeted within 14 days of paid-term end, subject to backups and legal retention. Account contact and billing-contact details follow the 7-year retention window in Billing and transaction data below.
Billing and transaction dataSubscription administration and payment processing (via Stripe).Duration of the subscription plus 7 years for tax, accounting, and audit obligations.
Workspace customer content and evidence filesThe policies, evidence, mappings, and exports a customer creates or uploads.While the subscription is active; primary deletion targeted within 14 days of paid-term end, subject to backup and legal-retention windows.
Reviewer and Trust Center access dataReviewer invitations, access status, and activity logs for customer-directed sharing.24 months.
AI prompt, output, and metadata logsOperating Aurora Copilot and AI-assisted drafting features.90 days, unless the customer configures a longer window through an approved mechanism or a separate written agreement.
Training and acknowledgment recordsReadiness records such as policy acknowledgements and training completions.Duration of the subscription plus 12 months.
Support and account recordsSupport tickets, correspondence, and account-service history.Duration of the subscription plus 36 months.
Usage, device, and audit-log dataSecurity monitoring, troubleshooting, and product analytics.Varies by log type; security and audit-relevant logs may be retained longer.
Lead and demo request dataFollowing up on contact-form and walkthrough requests.24 months from the last interaction, then deletion or de-identification.

Source: Privacy Policy §9 (Retention). When a self-service subscription ends, the customer is responsible for exporting data before the paid term ends.

Backups, encryption, and AI

Backups, Encryption, and How AI Features Handle Customer Data

Sourced from the Data Processing Addendum's security schedule and Aurora's Terraform infrastructure configuration.

ImplementedEncryption in transit

TLS is enforced for the public site and application, with HTTP Strict Transport Security enabled (max-age one year, including subdomains).

Source: deploy/nginx.ssl.conf.template

ImplementedEncryption at rest

The production application database is provisioned with storage encryption enabled, and evidence storage is encrypted with a dedicated per-tenant key, versioned, and blocked from public access. Aurora's Data Processing Addendum describes protection for data at rest as applied where appropriate to the environment.

Source: terraform/modules/tenant_stack/main.tf (storage_encrypted, per-tenant KMS key); DPA Schedule 2

ImplementedBackups

Short-cycle backups roll on a 35-day cycle. Longer-cycle backups, disaster-recovery media, and archival snapshots may be retained and deleted on a different cycle than live production data.

Source: Privacy Policy §9; DPA Schedule 2 (Business continuity and backups)

AvailableAI model providers

When Borealis provides the AI model workflow, requests route to approved OpenAI-hosted or Anthropic-hosted APIs. Customers may instead configure a customer-supplied API key, in which case requests use that customer's own provider account.

Source: AI Notice; Privacy Policy §7

AvailableDoes Customer Data train AI models?

No. Unless a customer expressly opts in through a Borealis-approved mechanism, or a separate Borealis-signed agreement says otherwise, Borealis does not use Customer Data from Aurora Command workspaces to train generalized or shared AI models.

Source: Privacy Policy §7; AI Notice §2

No method of storage or transmission is completely secure, and Borealis cannot guarantee absolute security. Source: Privacy Policy §8.

Related Trust Resources

See the full subprocessor register, the security one-pager, or the assurance roadmap.

Email privacy

This page summarizes the Privacy Policy and Data Processing Addendum. Where those documents and this page differ, the signed agreement and DPA control.