Trust at Tenure

This page explains how Tenure handles your agency's data, who can access it, what we delete and when, and what we keep for audit. We update this page when our practices change.

Data we capture

Tenure captures institutional knowledge through passive audio recording during seven consecutive workdays. The consented employee wears a lapel microphone. Audio is routed directly to Tenure's secure vendor infrastructure — it never touches agency systems. Transcripts and extracted SOPs and knowledge nodes are reviewed by a Tenure specialist before being published to the wiki.

No AI output reaches your team unreviewed. Every published item passes through a Tenure specialist review gate.

How we store it

All data is stored in US region only — AWS us-east-1 or us-west-2. Data is encrypted at rest and in transit. Raw audio is never served to humans via signed URL; only Tenure staff with a valid session can access audio files during the transcription window. Transcripts are accessible to Tenure administrators only and are not exposed in the wiki.

Audio deletion

At engagement close, raw audio files are hard-deleted from storage and the deletion is verified (404-check). Biometric artifacts and raw transcripts are also deleted. A Certificate of Destruction PDF is issued to your agency administrator within 30 days. A final certificate is issued after Supabase backup retention expires, confirming complete removal from all backups.

Audit log retention

Every action on extracted content — approve, reject, flag, edit, export, view, search — is logged with user identity, timestamp, and field-level diffs where applicable. Audit logs are append-only and retained for 7 years to support FOIA requests and SOC 2 evidence. Your organization administrator can export the audit log at any time.

Your rights

Any agency staff member can flag an SOP or knowledge node as outdated using the “Flag as outdated” button on any entity page. Your administrator will review flagged items. For questions about specific data handling, contact your Tenure specialist or your organization administrator.

Tenure is built around a single product promise: no AI output reaches your team unreviewed. Every published item passes through a Tenure specialist review.