- Commented out 'View RF Links' button in network map node detail panel - Commented out RF Link health legend (Good/Degraded/Critical) from map legend - Backend code (topology.ex) left intact per instructions - No RF tab found on device show page (nothing to hide there) - All tests pass, compiles clean with --warnings-as-errors Reviewed-on: graham/towerops-web#46
2 KiB
2 KiB
Data Handling & Retention Policy
Effective: 2026-03-15 Owner: Engineering & Operations
Purpose
Define how TowerOps stores, processes, backs up, and disposes of customer data to ensure reliability, compliance, and trust.
Encryption
At Rest
- Database: PostgreSQL with encrypted tablespaces or full-disk encryption.
- Secrets (API keys, SNMP communities, integration tokens): encrypted using application-level encryption (
Cloakor equivalent) before storage. - Backups: encrypted before writing to storage.
In Transit
- All external connections over TLS 1.2+.
- Internal service-to-service: TLS or encrypted tunnel (Cloudflare Tunnel, WireGuard).
- SNMP v3 preferred where supported; v1/v2c community strings treated as secrets.
Backups
- Database: daily automated backups with point-in-time recovery.
- Backup retention: 30 days.
- Backup restoration tested quarterly.
- Backups stored in a separate location from primary data.
Data Processing
- SNMP polling data processed and stored within the customer's org scope.
- No cross-org data aggregation without explicit anonymization.
- Metrics downsampled after retention window (raw → hourly → daily).
- Background jobs operate within org context; job payloads contain
org_id.
Data Disposal
- Deleted records soft-deleted for 30-day grace period, then hard-purged.
- Purge jobs run nightly to remove expired soft-deleted records.
- Customer account deletion triggers full data purge after grace period.
- Credentials from revoked integrations deleted immediately (no grace period).
Access Controls
- Role-based access:
owner,admin,member,viewer. - API tokens scoped to organization; cannot access other orgs.
- Token rotation supported; old tokens invalidated on rotation.
- Session timeout: 24 hours idle, 7 days absolute.
Audit Trail
- All data mutations logged: who (user/agent), what (action), when (timestamp), context (org, resource).
- Audit logs immutable — append-only, no deletion.
- Retained for 1 year minimum.