Sensitive data stays scoped, encrypted, and operationally accountable.
This is the current production handling model for tenant inventory, identity records, public intelligence, notification credentials, logs, backups, and incident recovery.
PUBLIC BETA DISCLOSURE · UPDATED SEPTEMBER 12, 202601 / CLASSIFICATION
Sensitive tenant inventory is envelope-encrypted per organization before it reaches Cloudflare D1. Hosted master keys and service secrets are held as Cloudflare Worker secrets rather than committed with source. Audit and shared operational messages use masked or redacted identity and tenant details.
03 / RETENTION
Beta data is retained only while it has an operational purpose.
Active organization configuration and inventory remain while the organization participates in the beta. Incident history, audit records, delivery records, and health telemetry are retained to explain decisions, investigate failures, and protect the service.
Retention periods are being measured during beta and may be shortened as operating requirements become clear. Owners can request export or deletion; legal, security, and recovery requirements may delay final removal of a limited subset.
04 / BACKUP & RECOVERY
Recovery preserves the same data protections.
Cloudflare D1 Time Travel and controlled exports support recovery. Encrypted tenant fields remain encrypted in snapshots and exports. Restore procedures are rehearsed in an isolated database, reconciled by counts and protection checks, and removed when the rehearsal is complete.
05 / INCIDENT HANDLING
Contain, assess, recover, and communicate.
When a security or availability event is suspected, operators can disable or rotate affected credentials, preserve audit evidence, roll back a Worker version, or recover D1 data. Scope and tenant impact are assessed before affected beta participants are contacted through established support channels. Sensitive contents are excluded from shared incident notifications.
06 / DELETION & EXIT
Leaving the beta includes a controlled data exit.
Organization owners may request an export followed by deletion through their onboarding contact or authenticated Support control. SphynxOC verifies authority, removes active tenant records and routes, and allows remaining encrypted recovery copies to expire under the hosting provider’s recovery lifecycle.