How CUBE OneCare stores, retains, and manages the lifecycle of trust-related data.
Trust artifacts, exports, and generated documents are stored through a unified storage layer that supports both local development and cloud-based object storage (S3-compatible). The storage adapter is configured per-environment via environment variables.
Storage references are recorded alongside integrity checksums in the database for audit traceability.
Retention periods are configurable and subject to legal hold overrides.
When a legal hold is active, no covered data may be purged regardless of retention schedule. Legal holds are managed through administrative controls with full audit trail. Only authorized administrators can set or remove holds.
Data purge operations are controlled processes that require administrative authorization and record the action, actor, and reason in operational event logs. Purge operations check for active legal holds before execution.