Skip to content
SmiKar Software

Data Retention and Storage

4 min read · Last updated · Page version 1

Where Burrow's data lives, how long it stays there, and what happens to it as it ages.

Everything on this page is fixed product behaviour - the same on every deployment. None of it is per-tenant configuration that you or SmiKar tune, which means the answers here are the answers for your environment too.

What is kept, and for how long

DataKept hot (instant search)Then
Per-event audit detail - behind Hunt, activity reports and alert evidence14 daysCompressed and archived to your Azure Storage account. Retrievable in minutes via Hunt → Cold Storage → Rehydrate.
Alert files - full evidence and AI triage detail14 daysArchived the same way. The alert's summary, verdict and disposition stay on the History page indefinitely.
Behaviour baselines - each person's "normal"Rolling: recent pattern 30 days, longer-term references up to 90 daysDaily rollups for people inactive more than 35 days are archived. An active person's baseline never leaves the appliance.
Alert outcomes, dispositions, admin audit logIndefinitely, as compact summariesNever archived, never deleted. This is your compliance trail.
Full-system backupSnapshot every 6 hours to your Azure Storage accountSnapshots older than 90 days are deleted automatically.

The four points that matter in a compliance conversation

The archive is yours, and Burrow never deletes it. Cold-storage data lands in an Azure Storage account in your subscription, under your ownership. Burrow writes to it, and reads from it on rehydrate, but never purges it. How long you keep archived audit history - seven years is a common policy - is enforced by you, typically with an Azure lifecycle-management rule on the container.

The consequence worth stating plainly: removing Burrow, or ending the service, leaves your archive intact and readable. Your audit history is not held inside a vendor system you would lose access to.

Nothing is lost at the 14-day mark. The hot window is about disk economy on the analysis machine, not about retention. Archived events and alerts are the same records, compressed - a rehydrate brings any month back into Hunt. The distinction is search latency, not existence.

Microsoft's own audit feed only reaches back 7 days. Burrow captures events within minutes of Microsoft publishing them, so once a record is older than a week, the archive - not Microsoft 365 - is your durable audit record. This is the answer to "can't we just get this from Microsoft?" during an investigation: after seven days, no.

Backups are belt-and-braces, not the archive. The six-hourly snapshots exist to rebuild the analysis machine after a failure. The 90-day purge applies only to those snapshots - never to archived audit data. Do not read the 90-day figure as a retention limit on your audit history; it is not.

Common questions

"How far back can I search right now, without waiting?" 14 days. Beyond that, rehydrate the months you need - typically ready in under a minute for a single user-month.

"Our policy requires seven years of audit history. Can Burrow do that?" Yes, and it is your storage account that enforces it. Burrow archives into it and never deletes; you set the lifecycle rule that defines seven years. The retention guarantee is yours to make and yours to prove.

"What happens to our data if we stop using Burrow?" The archive stays in your Azure Storage account, in your subscription, readable without Burrow. See no data hostage - the archive is deliberately not somewhere you would lose it.

"Is the compliance trail affected by any of this?" No. Dispositions, alert outcomes and the admin audit log are kept indefinitely as compact summaries and are never archived or deleted. The History page remains complete regardless of how old the underlying events are.

See also


Need help? support@smikar.com.

More in Squirrel

See all pages →