Data purge rules

Updated at:

Security Center purges your service data if your service expires because of an overdue payment, you unsubscribe from the service, or you close your Alibaba Cloud account. This topic describes the data purge rules.

Data purge scenarios

  • Service termination (account retained):

    • Pay-as-you-go (postpaid) service

      • Overdue payment: Pay-as-you-go bills are generated daily. An overdue payment occurs if your account balance is insufficient to cover the bill.

      • Manual service shutdown: If your account has no overdue payments, you can shut down the pay-as-you-go service.

      • Forced service shutdown: If events such as a breach of contract, fraud, infringement, or customer bankruptcy occur, Alibaba Cloud will forcibly shut down the pay-as-you-go service in accordance with the service agreement.

    • Subscription (prepaid) service

      • Expiration: The subscription service expires and is not renewed on time.

      • Manual unsubscription: You manually unsubscribe from the service before it expires without closing your account.

      • Forced unsubscription: If events such as a breach of contract, fraud, infringement, or customer bankruptcy occur, Alibaba Cloud will forcibly unsubscribe the subscription service in accordance with the service agreement.

  • Membership termination (account closure):

    • You manually close your Alibaba Cloud account.

    • Alibaba Cloud forcibly closes your Alibaba Cloud account in accordance with the service agreement because of events such as a breach of contract, fraud, infringement, or customer bankruptcy.

Service termination (account retained)

Pay-as-you-go service (postpaid)

Unified sales features

  • Overdue payment: After an overdue payment, a 15-day data retention period is provided.

    Important

    Alibaba Cloud offers a service suspension extension that can extend the data retention period for cloud products. For more information, see Service suspension protection for overdue payments. For example, if you are granted a 10-day service suspension extension, the data retention period for Security Center is extended to 25 days (10 + 15).

  • Manual service shutdown/Forced service shutdown: No data retention period. Data is immediately purged according to the rules.

Scenario

Data purge description

Overdue payment - Within the data retention period

During the retention period, all service authorization information, configuration policies, and pay-as-you-go service data are retained.

Overdue payment - After the data retention period

  • The following authorization information is immediately purged:

    • Container Protection - Image security scan.

    • Container Protection - CI/CD integration settings.

  • The following Agentic SOC data is immediately purged:

    Important

    If the data retention period for an overdue payment is longer than 15 days, Agentic SOC does not wait for the retention period to end. Instead, it starts the data purge immediately after the 15th day of the overdue payment.

    • Security alerts: All alert information except for alerts under CWPP.

    • Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).

      Note

      Security events generated from alerts under CWPP (CWPP security events) are retained.

    • Response orchestration: Custom playbooks and custom response rules.

    • Log Management: Standardized integration logs and Security Center logs.

    • Rule management: Custom rules.

    • Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.

  • Agentic SOC - Response Center: Response policy and response task data is automatically purged by the system 90 days after it expires. This is not affected by overdue payments or service shutdowns.

  • Cloud Security Posture Management:

    • Cloud product configuration check:

      • After the cloud product configuration check is disabled, the check result data is not deleted.

      • Periodic scan policies, allowlist policies, and custom check items are not deleted.

    • System baseline:

      • Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.

        Note

        If your subscription service (Advanced, Enterprise, or Ultimate) has not expired and has not been unsubscribed, the check results for the corresponding edition are continuously retained. After the service expires or you unsubscribe, the data is retained in the backend for 30 days and then automatically deleted.

      • Scan policies are immediately deleted. Allowlist policies are not deleted.

  • Anti-ransomware: 1 day after the instance is released, the protection capabilities and generated backup data of this service are removed.

Manual service shutdown

Forced service shutdown

Independent sales features

Agentic EDR

  • Elastic protection: Elastic protection immediately becomes invalid and billing stops. The elastic authorizations and credits consumed on the current day are billed the next day.

  • Data retention:

    • Policy and baseline retention: Existing policies and host baselines are retained but no longer updated.

    • Historical alert retention: Existing host anomaly alerts are retained, but no new alerts are generated.

Attack Management

  • Feature policy configuration data is retained permanently.

  • Asset and attack path scanning task data is retained for only 7 days and then permanently released.

Subscription service (prepaid)

Unified sales features

  • Expiration: A 7-day grace period is provided after your service expires. After the 7-day grace period, the service instance is immediately released. This means your paid or trial edition is downgraded to the Free Edition, and the corresponding data is purged.

  • Manual/Forced unsubscription: The service instance is immediately released. This means your paid or trial edition is downgraded to the Free Edition, and the corresponding data is purged.

Scenario

Data purge description

Expiration - Within 7 days

The service authorization information, configuration policies, and service data for all features are retained.

Expiration - After 7 days

  • The following authorization information is immediately purged:

    • Container Protection - Image security scan.

    • Container Protection - CI/CD integration settings.

  • Log analysis: The data in the `sas-log` Logstore is immediately purged. This Logstore belongs to the Project that Security Center creates in Simple Log Service (SLS). The Project is named `sas-log-<Alibaba Cloud account ID>-<region ID>`.

  • Host Protection - Anti-ransomware: All backup policies and backup data are immediately purged.

  • Cloud Security Posture Management:

    • Cloud product configuration check:

      • Only the check results of free edition items are retained. The check results of paid edition items are immediately purged.

      • Periodic scan policies, allowlist policies, and custom check items are not deleted.

    • System baseline:

      • Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.

      • Scan policies are immediately deleted. Allowlist policies are not deleted.

  • Anti-ransomware: 1 day after the instance is released, the protection capabilities and generated backup data of this service are removed.

Manual unsubscription

Forced unsubscription

Unsubscription/Expiration - After 15 days

  • The following Agentic SOC data is immediately purged:

    • Security alerts: All alert information except for alerts under CWPP.

    • Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).

      Note

      Security events generated from alerts under CWPP (CWPP security events) are retained.

    • Response orchestration: Custom playbooks and custom response rules.

    • Log Management: Standardized integration logs and Security Center logs.

    • Rule management: Custom rules.

    • Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.

  • Agentic SOC - Response Center: Response policies and response tasks are automatically purged by the system 90 days after they expire. This is not affected by unsubscription.

Independent sales services

Agentic EDR

After an EDR instance expires or is unsubscribed, the instance is immediately released, and Agentic EDR immediately stops service.

  • Elastic protection: Elastic protection immediately becomes invalid and billing stops. The elastic authorizations and credits consumed on the current day are billed the next day.

  • Data retention:

    • Policy and baseline retention: Existing policies and host baselines are retained but no longer updated.

    • Historical alert retention: Existing host anomaly alerts are retained, but no new alerts are generated.

Attack Management

The Attack Management instance is immediately released and protection stops.

  • Burstable protection: Burstable protection immediately becomes invalid and stops billing. Elastic authorizations and credits consumed on the current day are billed the next day.

  • Data retention:

    • Feature policy configuration data is retained permanently.

    • Asset and attack path scanning task data is retained for only 7 days and then permanently released.

Agentic BAS

  • Expiration: Agentic BAS task data is retained for 15 days. After 15 days, the instance is released and historical data is purged. If you repurchase within 15 days, historical Agentic BASt task data can be restored.

  • Unsubscription: Online unsubscription unavailable. Please contact your business representative for manual processing.

SecOpsAgent

  • Expiration: After the service expires, you can no longer use the features of Security Agent.

    • The instance and data are retained for 30 days. If you reactivate the service within the retention period, you can continue to use the existing data.

    • If you do not renew the service within 30 days, the instance is released and the historical data is permanently purged and cannot be recovered.

  • Unsubscription: Online unsubscription unavailable. Please contact your business representative for manual processing.

Membership termination (account closure)

If your Alibaba Cloud account is closed, all Security Center data associated with the account is immediately and permanently deleted.

Warning

This operation is irreversible. Deleted data cannot be recovered.