Trust · Data handling
What we hold, why, and for how long.
Cantilever is an execution control plane. It holds the metadata required to govern and evidence a run — not your application data.
Data categories
- Identity metadata — authenticated principal, role assignments and JIT grants per run
- Inventory metadata — resource identifiers, tags, ownership and dependency relationships
- Execution records — parameters, policy decisions, logs, output artifacts and approval history
- ITSM references — RITM, change and issue identifiers linking runs to change records
- Telemetry references — deploy events and SLO signals correlated to executions
Handling principles
- Secrets are never persisted — credentials are injected at runtime and revoked on completion
- Execution records are immutable and retained per your configured retention policy
- Tenant data is isolated at the execution, catalog and inventory layer
- Customer-managed and air-gapped deployments keep all data inside your boundary
- Private model deployment means no prompt or telemetry leaves your environment
- Data residency follows your deployment model and cloud region selection
Detailed documentation
Data flow diagrams, retention schedules, sub-processor lists and DPA templates are available on request for active evaluations. Contact hello@cantilever-engineering.com or request an architecture review.