Understand data collection and retention

See which metadata AegiFlow collects, what is excluded by default and how tenant access is constrained.

Expected result

The organization can document its approved telemetry and retention boundary.

Default collection

AegiFlow prefers bounded metadata: service, route, rule identifiers, result, timestamps and hashes. Full request bodies and direct personal identifiers are excluded by default.

Operational access is logged. Tenant data is restricted by application authorization and PostgreSQL row-level security.

Verification

  • Request bodies are not collected by default
  • Retention matches the selected policy
  • Audit access is scoped