Skip to main content

Data Ingestion and Retention at Guardz

Guardz platform retention vs. the Guardz DPA

The Guardz Data Processing Agreement (DPA) covers Guardz's data-processing and deletion obligations — including the deletion or return of customer personal data following service cessation, in accordance with the applicable deletion timelines. The DPA does not itself specify how long data is retained in the Guardz product during an active subscription, or how quickly Guardz actually deletes data on request. Those specifics are set out below.

What does Guardz Ingest?

Source

What Guardz ingests

Microsoft 365 / Entra ID, Google Workspace

Raw telemetry, ingested directly by Guardz — not Microsoft's or Google's own native alerts. This telemetry powers ITDR detection and supports investigations.

Third-party security tools (e.g., EDR, email security)

The full alert generated by the tool, plus its metadata. Benign content (such as email bodies or files) and continuous raw telemetry are not ingested by Guardz — that data stays within the third-party tool and may be accessed by Guardz on an ad hoc basis during an investigation.

Retention by Data Type

Data type

Retention period

Notes

Alerts, incidents, and issues (all sources)

Indefinite

Once an event from any connected source is surfaced as a Guardz alert, incident, or issue, it is retained indefinitely.

Ingested productivity cloud logs (Microsoft 365 / Entra ID, Google Workspace)

90 days from ingestion

Searchable by Guardz for analysis and investigation, not directly by the customer. If the source platform ages an event out of its own retention window sooner, Guardz's ingested copy still remains available for the full 90 days.

Underlying data in third-party security tools (e.g., endpoint telemetry, email content)

Set by the tool's own retention policy

This data is not ingested by Guardz (only the resulting alert and metadata are, per above), so it remains subject to that third-party tool's own retention policy, subscription tier, and any retention settings configured within the tool itself. Guardz may access this data on an ad hoc basis during an investigation.

"Guardz Managed" vs. Direct Use of Third-party Controls

Retention in a connected third-party security tool is not modified or shortened by being a "Guardz Managed" customer. It follows that tool's own policy, subscription tier, and configured settings, the same as it would for a customer using the tool directly.

Data Deletion after Account Cessation

When a customer's account is deleted, associated customer data is deleted within 24 hours. Ingested productivity cloud logs (Microsoft 365/Entra ID and Google Workspace) are the exception: they are deleted 90 days from their original ingestion date regardless of when the account itself is deleted.

Exporting Data

Alerts and issues can be exported via the Guardz API. Raw logs and underlying telemetry are not exportable by customers through Guardz; ingested cloud log data remains available for Guardz's own analysis for 90 days from ingestion.

Did this answer your question?