All systems operational
Security 8 min read

What we actually log, and for how long

Access logs, netflow and console history — what is retained, who can read it, and when it is deleted.

SO
S. Okafor
Security engineering

Privacy policies tend to describe categories rather than facts. This is the specific version: what exists, who can read it, and when it goes.

Client area access logs

Timestamp, source address, account and the action taken. Retained for 12 months. These are what let us answer "who changed this and when", which is a question customers ask us far more often than anyone else does.

Netflow

Sampled flow records — source, destination, ports, byte counts. No packet contents, because we do not capture them. Retained for 30 days and used for capacity planning and DDoS attribution.

Console and IPMI history

Connection metadata only: who attached to a console and when. The session contents are not recorded. Retained for 90 days.

Support records

Tickets and their attachments are kept for the life of the account plus 24 months, because a question asked in 2024 is routinely the answer to a question asked in 2026.

What we do not have

We do not inspect or store the contents of your traffic, we do not have your disk encryption keys, and we do not run agents inside your operating system. If you encrypt a volume, we cannot read it, and that is by design rather than policy.

Who can read any of it

Access is limited to on-call engineering and is itself logged. Requests from law enforcement are reviewed individually and we require valid legal process; where we are permitted to notify you, we do.

SO
S. Okafor
SECURITY ENGINEERING · SERVERMONKEY

Handles hardening, disclosure and the retention policy. Would rather publish the boring specifics than a reassuring summary.

Related reading