The audit record holds agent names, application identifiers, findings, timestamps and send history. It carries no client names.
When a client name has to appear on an owner report, it is read from your own ledger at the moment the report is built, and left blank if your ledger no longer carries it.
The record of each file audited is metadata: file name, byte and row counts, field names, and how many values each field held. No rows. No field values.
A snapshot of that record and of your configuration is encrypted with a public key and copied off the machine to write-once storage at every restart.
Beyond those categories the record holds nothing about a consumer: no client name, no date of birth, no Social Security number, no address, and no row copied out of an export.
The record lives on a single machine with full-disk encryption, and the copy that leaves it is encrypted with a public key before it goes.
Contractual terms covering material an agency sends — custody, handling, and the obligations on each side — are set out in the customer agreement, and we walk a compliance reviewer through them on the call.