Backup and Restore Service  ·  View 13 of 26  ·  4 · Data

Retention and Custody Lifecycle, by Tier

How long each kind of copy lives, where it is held, what can extend it, and what it takes to end it.

Editable source SVG draw.io All views
Written Copied Aged Held Expired Disposed Tier 1 Lock 35 d monthly 12 mo B + weekly tape HDD pool Restore extends lock Disposal worker Certificate Tier 2 Lock 30 d monthly 12 mo B from Phase 2 HDD pool Restore extends lock Disposal worker Certificate Tier 3 Lock 90 d monthly 12 mo Other DC only Cold EC pool RTO +4 h Restore extends lock Disposal worker Certificate Regulatory set Lock 7 y B + monthly tape Tape primary Legal hold · dual Crypto-shred Certificate Deleted resource Firebreak 90 d Owner confirms Disposal worker Certificate Retention and Custody Lifecycle, by Tier Shortening any lock needs two custody officers. Extending one needs nobody, because it can only make things safer. v 1.0 · owner Custody · date 2026-09

Decisions

  • Retention depth is set by the corruption detection window. With an assumed 30 days to notice logical corruption, Tier 1 keeps 35 days of PITR and 12 monthly copies, not 7 days of snapshots.
  • A restore extends the lock on the artefacts it reads by 7 days before reading. Extending retention needs no approval because it can only make data safer, and it closes the race of a copy expiring mid-restore.
  • Tier 3 copies are written to the custody cluster in the opposite data centre from their source, so losing a site never takes a bucket and its only copy together.

Numbers

  • Custody A holds about 5 PB usable at the retention horizon. That assumes the 3% daily change is all new bytes, which is the pessimistic case. Custody B is sized at about 4 PB.
  • Deleted-resource firebreak: 90 days regardless of tier, because the deletion may be the incident.

Risks

  • Lawful erasure and immutable tape conflict. The regulatory set uses a data key per datastore per month, so erasure is done by destroying the key. The certificate states the date the last key-ledger backup that held that key expires.