Skip to main content

Two-Tier Storage Model

Tier 1 — Ephemeral (Default)

All assessments use the ephemeral tier unless the client opts in to retained storage during onboarding.

AttributeValue
DefaultYes — applied to all assessments automatically
Contentscollection.json.enc + report.pdf.enc
TTL48 hours from report delivery confirmation
Deletion triggerTTL expiry — store-native mechanism, not application logic
EncryptionAES-256 at rest, TLS 1.3 in transit
AccessAssessment Engine service identity only — read once during assessment job
Operator accessNone — CYC staff cannot read contents
Client accessNone — client receives the report only, not raw data

Tier 2 — Retained (Opt-In)

Clients who opt in have their data moved from ephemeral to retained after report delivery. This enables Tier 2 consultation and Tier 3 drift detection.

AttributeValue
DefaultNo — client must opt in before payment
Contentscollection.json.enc + findings.json.enc + report.pdf.enc
TTL90 days from report delivery — or immediate on client deletion request
EncryptionAES-256 at rest, TLS 1.3 in transit
AccessAssessment Engine (drift), CYC Tier 2 analyst (read-only, audit-logged)
Permitted usesFollow-up analysis, Tier 2 consultation, Tier 3 drift detection, responding to client questions
Prohibited usesTraining AI models, benchmarking against other clients, sharing with third parties
Client deletion

Clients can request immediate deletion of retained data at any time via the CYC account portal. Deletion is confirmed by email within 24 hours. See Client Deletion Request Process.