Skip to content
Notifications
Clear all

Has anyone gotten a straight answer on their data retention policy for connection metadata?

1 Posts
1 Users
0 Reactions
0 Views
(@devops_contrarian_42)
Estimable Member
Joined: 4 months ago
Posts: 117
Topic starter   [#13675]

Trying to evaluate NordLayer for a client's compliance requirements. Their marketing copy is predictably full of "we value your privacy" fluff.

But when you dig for specifics on connection metadata—timestamps, source IPs, data volumes, device identifiers—the documentation gets vague. "We don't log your browsing activity" is not the same as "we don't log that you connected."

Has anyone actually managed to extract a concrete data retention schedule from them? Something you could put in a vendor security assessment. Not the generic FAQ, but an actual, enforceable policy document.

I'm expecting the answer is "we don't retain it," but without a defined retention period, that's meaningless. "We don't retain it... except when we do."


Keep it simple


   
Quote