# Evidence retention and destruction policy

## Classes

### Raw restricted

Unredacted packet captures, screen recordings, test-account identifiers, APKs and correspondence attachments.

Default retention: 12 months after final publication or last active dispute, whichever is later. Extend only with a documented reason.

### Derived internal

Normalised event logs, redacted payload excerpts, hash manifests, reviewer notes and endpoint-attribution tables.

Default retention: 36 months after publication. Preserve longer where needed to explain a correction or retest.

### Public sanitised

Receipts, method records, selected redacted evidence and institutional responses.

Retain indefinitely as the historical public record, subject to lawful removal and safety review.

## Destruction

- use cryptographic erasure or secure deletion appropriate to the storage medium;
- record artifact ID, deletion date, operator and reason;
- retain only the deletion record and prior public hash;
- never retain raw credentials merely because a story remains online.

## Access

Raw evidence is least-privilege. Access events are logged. Test-account secrets are kept separately from packet and screen evidence.
