Grotabyte
Contact SalesBook a Demo

Govern · Retention & Purge

Nothing is destroyed until two people agree — and then it's certified

Retention templates citing their statutes, a sweep that logs its exemptions instead of skipping them silently, dual-controlled suppression, four layers of destruction — and a certificate that queries the index before it says anything.

Grotabyte — Retention & Holds
SEC 17a-4(b) · 3 yearsenabled
Broker-dealer communicationsstatutory
FINRA 4511(c) · 6 yearsenabled
Books and recordsstatutory
Hold · Hendricks v. Acmepredicate
custodians: alvarez, chen · 2019 → present · matches future material toodual-control release
Longest applicable rule wins · clock runs from custody · refused erasures are ledgered

Where it starts

Everything ships out of force, and that is the safe state: a new archive keeps everything, and the screen says so — 'No retention rule is in force, so nothing is ever disposed of.' Destruction begins only when you decide the schedule.

How it runs

  1. 01

    Enable rules with their citations

    Ten templates, six citing their statute — SEC 17a-4(a)/(b), FINRA 4511(c), SOX §802, HIPAA, MiFID II. Two principles are stated before you enable anything: the longest applicable rule wins, and the clock runs from when this archive took custody — counting from the message date would make migrated mail disposable on arrival.

  2. 02

    Preview before anything is in force

    A rule can be scoped and previewed while disabled: what it governs, what is past retention, where the cutoff falls — and when another rule blankets it, the screen names the blocker in a sentence rather than showing a mysterious zero.

  3. 03

    Sweep, and read the exemptions

    The sweep disposes only when retention has expired and no hold applies. Exemptions are logged, not skipped silently — one ledger entry per hold, because customers under scrutiny must prove they preserved everything under hold, and those entries are that proof.

  4. 04

    Suppress under dual control

    Suppression stages the documents under an approval request — 'Nothing has been destroyed yet — no key has been touched' — for a different person to approve within 24 hours. The requester cannot approve it, and neither can anyone else who asked for the same act.

  5. 05

    Reclaim, then certify

    Crypto-shred first (the record key dies; the sealed container is untouched), then physical reclamation from the lakehouse and index. Only after reclamation is the certificate issued.

Why it holds up

Four layers, stated on the certificate: key destroyed (immediate) · lakehouse rows rewritten out · index splits rewritten · ledger never purged — the disposition entries are the proof.
The certificate queries the search index at issue and reports clear, residual, or unverified in plain words — the previous design asserted tombstoning that was never checked, and that sentence is gone.
Shared attachments are named, not hidden: an attachment still referenced by a held message is listed in shared_natives_retained rather than implying a destruction that did not happen.
The suppression-to-reclamation gap is disclosed with both timestamps — read surfaces exclude the documents from the first moment either way.
GDPR Art. 17 erasure rides the same mechanics: key destruction works on write-once storage, dual-controlled, and never overrides a hold — the conflict is surfaced, not resolved.

What you hand the regulator

A workflow that ends on a screen isn’t finished. This one ends in a document.

Certificate of destruction

Issued only after physical reclamation, and honest about everything a challenge would probe: what was destroyed, what could not yet be, and what the index said when asked.

  • documents destroyed · not yet certifiable · shared natives retained (named)
  • method: the four destruction layers, stated
  • index verification at issue: clear / residual / unverified
  • suppressed_at · reclaimed_at · the gap disclosed
  • ledger verification: chain intact at issue

Adjacent workflows

Matters & Legal HoldsChain of Custody & AuditSupervision & DLP

See it run on your data scenario

The demo form asks which workflows you want to see — name this one and we’ll stage it.

Book a DemoAll workflows

Stay in the loop

Subscribe to receive the latest product releases, compliance insights, and event invites from Grotabyte.

Grotabyte

Next-generation enterprise archiving and eDiscovery platform trusted by leading organizations worldwide.

Secure • Scalable • Reliable

Platform

  • Solutions
  • Features
  • Workflows
  • Data Sources
  • Email Archiving
  • Data Archiving
  • Records Management
  • Compliance

Industries

  • Financial Services
  • Education
  • Government
  • Healthcare
  • Public Safety

Resources

  • Complete Guide
  • Glossary
  • Compare
  • Case Studies
  • Whitepapers
  • Blog

Company

  • About
  • Contact

Trust & Legal

  • EULA
  • Support Terms
  • Privacy Policy

© 2026 Grotabyte. All rights reserved. Built with enterprise security and compliance in mind.