Data Retention & Disposal Policy

1. Key Rotation Schedule

To satisfy SOC2 and PCI-DSS requirements for "Periodic Key Rotation," BlindVault enforces the following:

2. Secure Disposal

3. Logs and Metadata

Access logs are retained for 1 year to satisfy audit requirements for SOC2 and PCI-DSS, after which they are automatically purged.