| Security telemetry |
Process execution, network flow metadata, authentication events, cloud audit logs |
Detection, investigation, threat hunting |
90 days hot, 365 days cold |
30–2,555 days, per data type |
| Detection and case data |
Alerts, incident timelines, analyst notes, response actions |
Investigation and audit |
Life of contract + 90 days |
Exportable at any time |
| Asset and identity inventory |
Hostnames, operating system versions, user principal names, group membership |
Scoping, risk prioritisation, containment |
Life of contract |
Field-level masking available |
| Sample artefacts |
Suspicious binaries and scripts submitted for analysis |
Malware analysis and detection engineering |
180 days |
Opt out of upload entirely |
| Content inspected by DLP |
Document fragments matching a classification policy |
Data loss prevention verdicts |
Match metadata only, 90 days |
Content never leaves your tenant |
| Administrative data |
Console user accounts, roles, API keys, audit trail |
Access control and accountability |
Life of contract + 7 years for audit log |
Streamable to your SIEM |
| Service telemetry |
Sensor health, ingest volume, feature usage counters |
Reliability, capacity planning, support |
13 months, aggregated |
Pseudonymised by default |