Privacy Policy

Last updated: September 18, 2026.

Decoda processes customer workspace data to provide monitoring, alerting, governance workflows, and export functionality.

Data we process

How data is used

Data is used to authenticate users, operate workspace features, preserve auditability, and support incident response. We do not sell customer data.

Retention while your Pilot is running

Each class of data has its own retention period, because raw chain telemetry, a security case file, and an accountability log are needed for different lengths of time. While your Pilot is active, records older than the period below are removed automatically by Decoda’s retention worker:

DataRetained forThen
Telemetry (raw monitored-chain observations)90 daysDeleted
Detections180 daysDeleted
Alerts and findings180 daysDeleted
Incidents, timelines, investigations and response history365 daysDeleted
Evidence exports (database record and stored file)365 daysDeleted
Audit and security logs365 daysAnonymized, then deleted
An individual user’s identity data, on erasure request30 daysAnonymized

Settings → Security shows the period in force for each class, where it came from, and whether it is being applied yet: a period that has been configured but has not started applying is labelled as such rather than shown as active, and a class with no policy reads “no automatic deletion” rather than a number nothing applies. A workspace owner can shorten or lengthen any of these periods through Decoda’s API, or by asking us to; the change is audited and requires a recent re-authentication.

What happens when a Pilot ends

A Pilot evaluation is open-ended by default: it has no deadline and no deletion schedule, and the product does not show a countdown for one. A Pilot ends when Decoda ends it, or when a Pilot that was given an explicit end date reaches that date.

  1. Grace period — 30 days. Your workspace stays readable and your evidence stays exportable for 30 days after the Pilot ends. The end date and the scheduled deletion date are both shown in the product.
  2. After 30 days. Telemetry, detections, alerts, findings, incidents and evidence exports — including the stored export files — are permanently deleted, and audit logs are anonymized: the actor identity, IP address and event details are destroyed and only the action, the object, the timestamp and the integrity chain remain.
  3. After 365 days from the end of the Pilot. The remaining anonymized audit record is deleted as well.

If you upgrade, continue, or are reactivated at any point before the deletion runs, the scheduled deletion is cancelled and nothing is deleted.

What the schedule does not cover

The schedule above removes your operational security records. It does not remove your workspace configuration: the asset registry, monitoring targets and monitoring configuration, integrations and their stored credentials, API keys, webhooks, notification destinations, team membership and invitations, governance policies, and workspace settings are not on any automatic schedule. Removing them means deleting the workspace itself, which Decoda does on request — contact support@decodasecurity.com. Deleting your individual user account anonymizes your own identity and revokes your sessions; it does not delete the workspace. We list this rather than implying the schedule deletes everything, because it does not.

Requesting deletion earlier

A workspace owner or administrator can request immediate deletion at any time, through Decoda’s API or by contacting support@decodasecurity.com. The request requires a recent re-authentication and an explicit typed confirmation, is recorded in the audit log, and produces a deletion receipt — a hash of the deletion report, listing what was removed and how many records, and containing none of the deleted content. Deleted records cannot be restored through any Decoda API.

Legal holds

A legal hold placed on a workspace overrides every deletion schedule on this page, including an immediate deletion request. Data under hold is retained until the hold is released; the product states when a hold is blocking a scheduled deletion. Releasing the hold allows the normal schedule to resume.

Backups

Deleted data is removed from Decoda’s active systems on the schedule above. Residual encrypted copies may remain in our infrastructure providers’ backups until their normal backup-retention cycle completes, after which they are overwritten. We do not claim that deletion is instantaneous across backups, and we do not claim that no residual copies remain.

Security and subprocessors

Decoda relies on cloud infrastructure and operational subprocessors to host the service. We maintain least-privilege access, encrypted transport, and workspace-scoped controls as described on the Security page.

Questions

Use the Support page for privacy, export, account, or incident communication requests, or contact support@decodasecurity.com.