Data map

Every category of data RadiantOS stores, where it lives, and how long it's kept. Tenants elect US or EU at signup; data stays in the chosen region.

CategorySub-processorRegionsRetention
Tenant identity
Tenant name, billing address, owner email.
Vultr Managed PostgreSQL - tenants, profiles, user_tenants.
TLS 1.2+ in transit. Managed PostgreSQL encryption at rest.
VultruseuRetained for contract duration + 30 day grace after termination.
Account ownership, billing, RBAC.
End-user identity
Names, emails, device identifiers, IPs.
Vultr Managed PostgreSQL - profiles, contacts, rmm_agents.
TLS 1.2+ in transit. Managed PostgreSQL encryption at rest.
VultruseuSame as tenant identity.
Ticket routing, device attribution, MDM enrollment.
PSA ticket content
Ticket subject, body, attachments metadata, time logs.
Vultr Managed PostgreSQL - psa_tickets, psa_time_entries; Vultr Archival Object Storage - attachment blobs.
TLS 1.2+ in transit. Managed PostgreSQL encryption at rest. Vultr archive object storage server-side encryption.
VultruseuRetained for contract duration + 30 day grace. Configurable per tenant.
Support tooling.
Backup blobs
Restic repositories, SaaS backup payloads and export bundles.
Vultr Archival Object Storage - regional per-tenant buckets.
TLS 1.2+ in transit. Vultr archive object storage server-side encryption. Restic client-side AES-256 where applicable.
VultruseuPer-repo retention policy with legal hold override and configured cleanup windows.
Backup, restore, export and disaster recovery.
Vault secrets
Customer passwords, API keys, TOTP secrets and secret metadata.
RadiantOS first-party Vault service on Vultr VKE. Secret references live in managed PostgreSQL.
Client-side or envelope encryption where supported. Raw secrets are stored only in the vault/KMS tier, not Markdown, logs or analytics.
VultruseuRetained while referenced by at least one active entity, subject to offboarding purge and legal hold.
Managed credentials.
Payment data
Card tokens, billing history and invoice metadata. Card PANs never touch RadiantOS servers.
Stripe tokenized payment records plus RadiantOS managed billing tables for token references only.
Managed by Stripe for payment data. RadiantOS stores only token references and non-card metadata.
StripeusAs required by Stripe and billing obligations, typically 7 years.
Billing.
Transactional email
Recipient address, subject, HTML body and delivery events.
SendGrid in transit. Outbox rows in managed PostgreSQL before handoff.
TLS 1.2+ in transit.
SendGrid (Twilio)usEmail event logs 30 days in SendGrid. Outbox rows 90 days unless customer policy requires longer.
Notifications, report delivery and auto-ticket emails.
Anonymized product analytics
Event name, user or tenant pseudonymous identifier, route and product-usage property bag.
PostHog Cloud with sensitive fields masked.
TLS 1.2+ in transit.
PostHoguseuPostHog retention per configured project policy.
Feature adoption, funnel analysis, onboarding drop-off and product improvement.
Error telemetry
Stack traces, breadcrumbs, spans, scrubbed request metadata and release health.
Sentry with PII and secrets scrubbed before ingestion.
TLS 1.2+ in transit.
Sentryus90 days unless incident hold requires longer.
Bug triage and incident forensics.
Infrastructure and edge
Request headers, IP, TLS metadata and operational logs. No raw application secrets.
Cloudflare plus Vultr VKE/application logs.
TLS terminated at edge; origin connection TLS 1.3 where supported.
CloudflareuseuCloudflare 30 days, application logs 7 days unless an incident hold applies.
Edge routing, DDoS protection, platform observability and security operations.