Log Retention Policy

This is an article title Copy Copy

Last updated: August 31st, 2026

1. Purpose

This policy defines how Aethex classifies, retains, and disposes of log data across its production systems. It ensures security-relevant records are kept long enough to support incident investigation, audit, and regulatory obligations, while operational logs are retained only as long as they are useful, consistent with data-minimization principles.


2. Scope

This policy applies to all log data generated by Aethex production infrastructure and applications, including cloud provider activity logs, infrastructure and platform logs, and application runtime logs.


3. Log classification

Logs fall into two categories:

  • Security and audit logs: records used to establish accountability or investigate security events. This includes cloud provider account and API activity, infrastructure and cluster control-plane audit and authentication events, and security-relevant application events such as authentication, authorization, and administrative actions.

  • Operational logs: application and service runtime and diagnostic output used for troubleshooting and performance monitoring. These are not records of security events.


4. Retention schedule

Log category Minimum retention Storage Security and audit logs 365 days (12 months) Cloud provider audit logging service and durable, access-controlled object storage Operational logs Up to 30 days Centralized logging service, used as a short-term operational forensics window


Where a specific security, contractual, or regulatory requirement calls for longer retention, the relevant logs are archived to durable, access-controlled object storage for the required period.


5. Protection and minimization

  • Credentials and secrets are redacted from log records before storage.

  • Operational logs are minimized and are not retained beyond their operational purpose. Personal data present in logs is subject to the same minimization and is not retained longer than necessary.

  • Logs are encrypted at rest, and access is restricted to authorized personnel.


6. System of record

Aethex does not treat its short-term operational log store as its long-term audit archive. Cloud provider account and API activity, and infrastructure and cluster control-plane audit events, are retained for at least twelve months in durable, access-controlled storage. Operational logs are retained per the schedule in section 4 and are not relied upon as security records.


7. Exceptions

Any deviation from this policy must be documented and approved by the policy owner, with the rationale and any compensating controls recorded.

The voice AI stack for emerging markets.

See agents in production, configured for your use case, your market, your systems.

Screenshot of the Aethex logo

© 2026, AethexAI Inc.

The voice AI stack for emerging markets.

See agents in production, configured for your use case, your market, your systems.

Screenshot of the Aethex logo

© 2026, AethexAI Inc.

The voice AI stack for emerging markets.

See agents in production, configured for your use case, your market, your systems.