Skip to main content
Unbound records what your AI tools do so you can read it later — a prompt from three months ago, the command that was blocked in April, the MCP call behind an incident. Very little of it expires on a timer. This page states what that means, so you can answer a security review from it.

The short version

Nothing in the product expires your activity data with age. Prompts, terminal commands, MCP tool calls, task rows, analytics, discovery inventory, policy decisions, spend records and webhook delivery history have no retention window. They stay available until you delete the object they belong to. One derived rollup is the exception, noted below. Five things do expire on their own: Those five are what the product itself applies. The storage behind exports and parked telemetry carries its own lifecycle rules; if a review needs a stated figure for those, ask support and we will put it in writing.

What you can delete yourself

A policy you delete stops applying immediately and leaves the list, and the record of what it did while it was live stays in your analytics and logs — so deleting a policy does not erase the evidence of an action it blocked.
Disconnecting an integration removes the credential, not the data. Removing the Anthropic connection stops further imports; the claude.ai chats already imported remain in Logs. Removing an MDM connection stops serial lookups; the devices already attributed stay attributed. Treat disconnecting as revoking access, not as a delete.

Where the sensitive content actually sits

Prompt and command text is the part a reviewer will ask about. It lives in three places: Every delivery carries the payload documented on Webhooks. Where a receiver is out of scope for your retention policy, narrow what reaches it: subscribe it to the per-action events rather than *.logged, and point it at a destination whose retention you control.

Closing an organization

Unbound can deactivate an organization on request: access is revoked, and traffic stops being accepted and recorded. That is a support operation, not a dashboard control, so it cannot happen by accident and can be confirmed in writing. Purging the data already recorded is a separate request, handled the same way. Email support@unboundsecurity.ai from an Admin account on the organization and say which of the two you need.
If your obligations require a fixed retention window — 90 days, a year, anything — say so to support rather than assuming one applies. There is no per-organization retention setting in the product today.