Skip to content
Notifications
Clear all

Anyone else's bill have hidden costs for data retention?

6 Posts
6 Users
0 Reactions
28 Views
(@jacksonj)
Estimable Member
Joined: 3 months ago
Posts: 64
Topic starter   [#10495]

Hey everyone! New Orca user here, just getting our SaaS ops set up.

Got our first bill and noticed some extra charges I wasn't expecting. They seem to be for keeping scan data longer than 30 days. Is that normal? The pricing page wasn't super clear on this, and our sales rep didn't mention it during onboarding.

Just trying to understand if this is a standard thing or if I need to adjust a setting somewhere. Want to make sure our reporting costs stay predictable!


Thanks!


   
Quote
(@db_diver)
Reputable Member
Joined: 7 months ago
Posts: 333
 

It's absolutely standard, though I understand the frustration when it's not clearly communicated. Most managed scanning/observability platforms tier their pricing by retention window. The base plan often covers 30 days for active querying, but longer retention for compliance or historical trend analysis is almost always a paid add-on.

You'll want to check your account's data lifecycle settings. There should be a policy configuration where you can define rules, like moving data to a cheaper cold storage tier after 30 days or deleting it outright. Without explicit rules set, the system defaults to keeping everything in the standard tier, which generates the higher cost.

This pattern is common across AWS, GCP, and Azure's managed services too - the operational data is cheap, but archival has a price.


SQL is not dead.


   
ReplyQuote
(@hiroshim)
Noble Member
Joined: 3 months ago
Posts: 767
 

> "Most managed scanning/observability platforms tier their pricing by retention window."

Exactly right. The pattern is standard, but the magnitude of the hidden cost often surprises teams because it scales with data volume, not just time. A 90-day retention policy on a platform that ingests 10 TB/month could easily triple the bill compared to the 30-day base tier, even before factoring in the cold storage transition fees.

One thing I'd add: the lifecycle rules you mentioned are critical, but the performance penalty for querying cold tier data is rarely documented. In my benchmarks on similar services (e.g., AWS OpenSearch cold storage vs. UltraWarm), query latency for the cold tier was 4-8x higher. If you have compliance queries that need to run on 60-day-old scan data, the "cheaper" cold tier might not meet your SLA. Have you tested query response times after setting up those policies?



   
ReplyQuote
(@devops_barbarian_v3)
Honorable Member
Joined: 6 months ago
Posts: 403
 

Yeah, they all get you on retention. Check your data lifecycle config. If you haven't set rules, it's probably keeping everything hot forever.

I set a rule to dump to cold storage after 30 days, delete after 90. Slashes the bill, but my queries for old reports are painfully slow now. Classic trade-off.

Always assume "standard tier" means "most expensive tier." Sales reps sell the base rate and hope you don't notice the data gravity tax.



   
ReplyQuote
(@emilyk22)
Honorable Member
Joined: 3 months ago
Posts: 465
 

The frustration is completely understandable. My team encountered this exact scenario, and it highlights a common gap between sales demos and operational reality. While others have correctly identified lifecycle rules as the fix, the challenge often lies in the granularity of those rules.

For predictable billing, you need to map retention rules to specific data *types* from your scans, not just a blanket timeframe. Vulnerability findings might need 90 days for remediation tracking, but raw asset inventory logs could move to cold storage immediately. Orca's policy editor should let you create these differentiated rules, which prevents unnecessary "hot" retention for low-value data.

Did your sales rep provide any documentation on the data schema or typical per-scan data volumes? Without that, it's very difficult to configure cost-optimal policies from day one.


Support is a product, not a department.


   
ReplyQuote
(@data_analytics_rover)
Prominent Member
Joined: 6 months ago
Posts: 611
 

Yeah, that's a common pain point. The baseline retention is often just a starting point for cost calculations. What's usually missing from the sales demo is the data volume multiplier.

If you're scanning a large environment, even a few extra days of "hot" data can create a surprisingly linear cost increase. I'd log into the console and check your daily ingest volume first. Then you can model the cost delta for, say, 45 vs 30 days. That gives you a concrete number to decide if you need stricter lifecycle rules or if the cost is acceptable for your reporting needs.



   
ReplyQuote