> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Control data privacy and retention

> Mask sensitive values before they reach an AI provider, set how long records are kept, export retention evidence, and delete an organization.

export const Plan = ({tier}) => <Badge color="blue">{tier} plan</Badge>;

Org admins control what leaves the organization toward AI providers, how long each kind of record is kept, and what happens when the organization is closed. These controls live under **Settings**.

<Plan tier="Free" />

All of them need the org admin role.

## Mask sensitive values in AI prompts

Data anonymization masks IP addresses, email addresses, internal hostnames, internal URLs and credential-shaped strings in prompts before they go to an external AI provider. The response is unmasked on the way back, so tool queries still reach your real hosts.

<Steps>
  <Step title="Open AI Providers">Click **Settings**, then the **AI Providers** tab.</Step>

  <Step title="Find Data Anonymization">
    The **Data Anonymization** switch is on this tab. It is on unless an admin has turned it off.
  </Step>

  <Step title="Change it if policy requires">
    Click the switch. A message confirms **Anonymization enabled** or **Anonymization disabled**.
    Every change is recorded in the audit log, and a support person viewing as you cannot flip it.
  </Step>
</Steps>

Masking can reduce the model's ability to correlate infrastructure, which is where investigation quality comes from. Keep it on when policy says raw infrastructure detail must not leave your tenant.

To see the effect, open **Security**, then the **AI Governance** tab (Business). It shows calls over the last 30 days with the share that were anonymized, and each call shows **Anonymized?** as **Yes** or **No**.

## Set retention

<Steps>
  <Step title="Open the retention table">
    Click **Settings**, then **Preferences**, and scroll to **Data Retention**. The same table is on
    the **Retention** tab of the **Security** page.
  </Step>

  <Step title="Set the window">
    Each row is a type of record, such as alerts, investigations, audit logs or findings. Change
    **Retain Days** and click the check mark.
  </Step>

  <Step title="Choose delete or archive">
    **Purge Mode** is **Delete** or **Archive**. **Archive** is disabled for record types that
    cannot be archived. A saved policy that cannot be archived says that nothing is being purged.
    Switch it to **Delete** if removal is what you want.
  </Step>

  <Step title="Enable and run">
    The **Enabled** switch turns a policy on or off. **Run Now** applies it immediately. **Last
    Run** and **Last Purged** show what happened.
  </Step>
</Steps>

Each record type starts with a default window, so a new organization is covered before you touch anything. Deleting an alert also deletes its investigations, with their findings, actions and reports. An alert is dated from when it resolved, so one that recovered through its own webhook is kept for your window.

Your plan sets the audit log retention ceiling, shown on the **Subscription** page under **Plan limits**.

<Warning>
  A purge is permanent. Export evidence first if an auditor may ask what your policy was.
</Warning>

## Export retention evidence

Click **Export evidence** at the top right of **Data Retention**. You download a zip with:

* Your retention configuration and the last purge run, as JSON for a script.
* The same information in prose for an auditor.
* A manifest with a checksum for each file.

Missing record types are filled in with their defaults, so nothing being purged is left out. Two things the export states rather than implies. A policy asking to archive a type that cannot be archived purges nothing, even though it records a run. And the purge history lists only runs that removed rows, so an empty history is not proof that retention never ran.

The download is recorded in the audit log.

## Delete the organization

The **Delete this organization** card is the last one on **Preferences**.

<Steps>
  <Step title="Cancel any paid plan">
    An organization whose paid subscription still grants access cannot be deleted. Cancel it on the
    **Subscription** page first. Deleting does not cancel billing.
  </Step>

  <Step title="Export what you want to keep">
    Deletion covers alerts, investigations, runbooks, SLOs, connectors, API keys, cards and member
    accounts.
  </Step>

  <Step title="Delete">
    Click **Delete this organization**, type the organization's slug when asked, and click **Delete
    organization**.
  </Step>
</Steps>

## What happens next

The organization stops resolving at once. Everyone signed in loses access the next time they load a page, and the public status page, webhooks and API keys stop working. Nothing is destroyed on the spot: contact support within about a month and the organization can be restored intact. After that it is removed permanently.

Organizations that nobody uses can also close on their own. The admins whose addresses were confirmed receive two warning emails first, and the closure is the same soft delete with the same restore window. Paying organizations are never closed this way.

## Related

* [Connect your data](/guides/get-started/connect-your-data): use only your own AI providers.
* [Review security findings](/guides/security-cost/security): review AI calls on the AI Governance tab.
* [Plan matrix](/guides/reference/plan-matrix): audit log retention on each plan.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.