TUCUNARStart monitoring

Data policy · v2026-09-02

Raw data stays where the operation runs.

Tucunar separates operational truth in ClickHouse from identity, tenancy and summarized health in the cloud control plane.

This is the technical data-boundary baseline. The customer-specific region, retention, deletion, backup and export commitments must be recorded in the order form or data annex before production.

1. Data ownership and location

DataSource of truthCloud treatment
Raw signals, payloads and dimensionsClickHouse on the selected nodeNot sent to browser, Vercel or Supabase
Rules and local evaluator stateNode configuration and ClickHouseNot replicated by default
Identity, organizations and membershipsSupabase control planeAuthorized console access only
Heartbeats, rollups and incidentsSupabase summarized control planeScoped by organization; no raw payload
Alert secrets and delivery metadataEncrypted control-plane records and durable delivery stateSecrets never shown to browser

2. Deployment profiles

  • On-premise: the customer controls the host, ClickHouse volume, backup destination and data residency. Tucunar requires outbound HTTPS only when cloud summaries are enabled.
  • Cloud-managed: Tucunar operates the node profile and must record the hosting region, access controls, backup policy and deletion process before customer production data is enabled.
  • Air-gapped: raw data, evaluation, dashboard and local alerts remain inside the isolated environment. Cloud reporting is disabled, so an external local monitor is required.

3. Retention baseline

DataBaselineOwner of final decision
Raw signal rows and payload TTL395 days by default; configurable from 1 to 3,650 daysCustomer/order form
Incident and local delivery state13 months in the node baselineCustomer/order form
Completed cloud outbox rows30 days; pending rows are not removed by TTLTucunar operating policy
BackupsOperator-defined and stored outside the application volumeCustomer for on-premise; Tucunar for managed cloud

4. Deletion, export and recovery

Before production, the parties must record how an organization requests control-plane deletion, how the customer exports authorized audit evidence, how node data and backups are deleted, and how long deletion may remain in immutable or offline backups. On-premise deletion is performed by the customer operator using the documented retention and storage procedures.

Backups are not a substitute for a deletion policy. Every pilot should record the observed backup and restore duration, recovered row count, target RPO/RTO and the responsible operator.

5. Minimization and support

Send normalized signals rather than credentials or complete provider payloads when they are not necessary. Configure redaction before insertion. Diagnostic exports should contain versions, readiness, bounded metrics and delivery status, never `.env` files, tokens or raw signal bodies.

6. Customer data annex checklist

  • Customer and Tucunar data owners.
  • Hosting profile, region, network egress and approved destinations.
  • Signal fields, personal-data assessment and redaction keys.
  • Raw, incident, outbox and backup retention.
  • Export, deletion, legal hold and restore procedures.
  • Subprocessors, support access and incident notification.