Data Retention
Default retention for the live DefendableCloud: receipts are retained as permanent books-and-records. Each receipt is hash-chained per-org in Postgres (DCR-{org_seq}-{hex8} · parent_hash links · sha256 over canonical JSON), so the chain is the record of permanent retention — verifiable end-to-end via /ledger/verify. Tigris artifact copies (JSON + PDF) are stored best-effort alongside the chain. Operators control what payload data they submit into a Run in the first place.
🐝 Operator-grade · books and records · to the shed.