Standard retention compared with ZDR
ZDR is not a stronger recovery mode. It is a reduced-custody mode with fewer
recovery, replay, export, and reconstruction semantics.
The current source row is customer-facing
preview, rollout_fenced,
admits only the zdr retention mode, and requires the hosted ZDR Runner
prerequisite plus release evidence. Those labels describe source posture;
the live endpoint must still report available: true for the selected
deployment and Workspace.
What may remain without execution content
Checkfu can retain non-content facts needed for governance, accounting, and safety, such as:- identifiers and sequence positions;
- timestamps and state transitions;
- authorization and policy dispositions;
- approval identity and decision;
- Usage units and monetary facts;
- content-unavailable reasons; and
- non-secret provider effect disposition.
Recovery and channels
A channel is ingress and presentation around a Session. It does not own a second transcript. Under standard retention, a qualified channel can rebuild presentation from retained Session truth. Under ZDR, content omitted from the Session cannot later be reconstructed by Checkfu. External channel providers can keep their own copies under their own policies. Checkfu’s retention mode does not erase provider-held mail, messages, files, or delivery logs unless an admitted provider operation explicitly does so and the result is observed. Plan 814 is in progress. Durable callback acceptance, observation recovery, and fenced presentation reconciliation have landed. Presentation-sink erasure integration and credentialed live-provider qualification remain open, so a retention mode or source adapter still does not establish complete channel custody or provider support.Export
GET /v1/sessions/{id}/export can return only what the caller is authorized to
read and what remains in durable custody. The export accounts for unavailable
sequence positions rather than fabricating content.
An export is a new downstream copy. Once written to your filesystem, object
store, SIEM, or data warehouse, it is governed by your retention and erasure
controls. A later Checkfu erasure cannot reach that copy.
See Export retained Session and audit records for
the current export boundaries.
Deletion and erasure
Use the terms precisely:- Archive changes lifecycle or mutability while retaining the resource.
- Delete removes the addressed logical resource according to its typed contract.
- Erase disposes of protected content and identity links across every sink included in the erasure contract.
Current limitation
Current implementation and verification evidence do not establish one linearized erasure fence across every historical execution frame and registered presentation sink. Plan 813 isIN PROGRESS: privileged trajectory export,
server-derived producer attribution, signed Bundle frontiers, Bundle
release/deletion ordering, and a durable Session-owned sink worklist have
landed. Current writes are retention-classified and ZDR avoids durable
HarnessLoop transcript bytes, but historical dormant custody and the Plan 814
presentation-sink handoff are not fully closed. Remote provider erasure or
revocation can also remain pending.
Therefore:
- stop new work and revoke relevant access before requesting erasure;
- cancel or quarantine in-flight exports and provider operations;
- treat downstream exports as separately governed copies;
- retain the Audit evidence for each disposal step; and
- do not describe erasure as complete until the deployment’s current evidence covers every required sink.