User guideAdministration

Data retention and the audit log

Data retention

On Data retention, an Organization admin sets how long each kind of data is kept. Data older than that is removed automatically every six hours.

Data Kept by default Can be set to
Telemetry (check-ins, scan history) 90 days 7 days to 10 years
Job output 180 days 7 days to 10 years
Reports 2 years 30 days to 10 years
Trends behind Analytics 3 years 30 days to 10 years
Audit log 7 years at least 1 year
  • Shortening a period asks you to Confirm shorter retention, because the older data goes for good.
  • Purge now removes data already past the policy straight away; nothing newer is touched.
  • The page lists what was removed recently.

The audit log cannot be set below a year, so the settings can never be used to empty the record of who changed them.

Audit log

Audit log records who did what, from which address and when: sign-ins, changes to users and settings, every job and who started it, approvals, exports and support access. Nobody can edit or delete an entry; entries leave only when they pass the audit log's retention period.

Organization admins, Security reviewers and Read-only auditors can read it.