Trust center / data lifecycle

Know where an output came from and when it leaves.

Retention is selected per job, surfaced in lifecycle metadata, and paired with organization ownership, provenance, and explicit deletion.

Ephemeral

Use for short-lived processing when durable account storage is unnecessary. Clients must retrieve required output before expiry.

Temporary

Use for ordinary integrations and agent tasks that need a practical retrieval window but not indefinite account retention.

Account

Use only when the account needs a durable artifact. Policy expiry and explicit deletion still apply.

Deletion

Authorized deletion targets one terminal, organization-owned job and its retained outputs. The accepted operation is asynchronous; clients should confirm final state.

Provenance fields

Persist source identifiers, file checksums, job ID, output ID, profile, format, warnings, timestamps, manifest checksums, and expiry alongside downstream copies.

Search indexing boundary

Private jobs, user files, signed objects, control-plane pages, account content, and API routes are excluded from the public sitemap and disallowed for crawlers.