I have been conducting a preliminary evaluation of NordLayer's service, focusing not on throughput but on operational policies. A critical component of my assessment framework for any network security tool is the clarity and specificity of its data governance, particularly regarding connection metadata retention. My queries to their support team have yielded inconsistent and frustratingly non-reproducible results.
The stated privacy policy is characteristically high-level, using terms like "minimum data" and "for as long as necessary." This lacks the precise, quantifiable metrics required for a proper audit. I need to establish a definitive baseline for the following data points:
* **Connection Timestamps:** Are initiation and termination times logged, and at what granularity (second, millisecond)?
* **Source IP Anonymization:** Is the original user IP address retained, hashed, or discarded immediately post-authentication?
* **Destination Tracking:** For how long are accessed resources (e.g., domains, IP:port combinations) stored in an identifiable form?
* **Data Aggregate Period:** What is the exact, fixed duration before raw metadata is aggregated or purged? Is this 30 days, 90 days, or a variable "as needed" period?
My support ticket interactions have followed a strict, repeated protocol, yet the outputs vary. The responses are paraphrased and lack citations to specific technical documentation. For example:
```
Ticket #1 Response: "We keep some connection data for service functionality but do not monitor or track user activity."
Ticket #2 Response: "Logs are kept for a short time to ensure network security and troubleshoot issues."
```
This is not a satisfactory dataset. The absence of a clear, public, and technically detailed data retention schedule is a significant variable. Without it, one cannot accurately model the privacy surface area.
Has any other member here performed a similar inquiry and received a documented, point-by-point specification? A link to an internal policy document or a definitive statement from a systems architect would be invaluable. I am particularly interested in whether the policy is uniformly applied across all infrastructure nodes or if there is regional variance, as this would introduce another confounding variable in the analysis.
-- bb42
-- bb42
Yeah, that "as long as necessary" phrasing always makes me nervous too. It's like the legal version of "I'll be there soon."
I was trying to figure out the same thing for a client audit last month. Got three different answers from chat support, so I just gave up and stuck with Google Workspace's VPN for now. Not as secure, but at least the policy is clear.
Did you try escalating to their actual compliance team? Or are they just impossible to reach?