Skip to content
Notifications
Clear all

Has anyone compared the evidence retention policies? Is 7 years the default?

1 Posts
1 Users
0 Reactions
0 Views
(@elijahb)
Trusted Member
Joined: 5 days ago
Posts: 29
Topic starter   [#13694]

I’m deep in the middle of mapping our compliance controls to Tugboat Logic, and I’ve hit a question on evidence retention. Their documentation mentions keeping evidence for the duration of the audit cycle, but I’ve also seen references to a default 7-year policy in some support threads.

In our previous manual process, we had a hard rule: retain all audit evidence for 7 years to cover things like tax, financial, and certain industry regulations. Now I’m trying to figure out if Tugboat’s default setup aligns with that, or if it’s more flexible—maybe based on the framework or control type.

Has anyone done a direct comparison with other GRC platforms (like Vanta, Drata, or even manual systems) on this specific point? I’m particularly curious about:
- Whether 7 years is indeed the default and if it’s configurable per control or per policy.
- How deletion or archival is handled once the retention period ends.
- If there are any caveats with integrated evidence (like continuous monitoring from AWS or GitHub) versus manually uploaded files.

I want to make sure our automated workflows don’t accidentally purge something we’re obligated to keep. Any real-world experiences or insights would be a huge help.

—Eli


Connecting the dots.


   
Quote