Security
Data deletion SLAs, retention limits, and controls for repository and secret access.
Ellipsis deletes data within 4 hours after its time to live (TTL) expires.
Data retention
| Data | Retention limit |
|---|---|
| Session data | Customer-configured TTL from 0 hours to 1 year |
| Other retained operational data, including webhook payloads | Maximum TTL of 3 days |
For example, data that expires at 12:00 UTC is deleted by 16:00 UTC. A TTL of 0 hours means data is deleted within 4 hours. Export records you need before their TTL expires.
GitHub access
Choose which repositories the GitHub App can access, then limit each session's GitHub permissions.
Secrets
Store credentials as secrets; stored values can't be read back through the dashboard or API. See Permissions for what a session can do with them.
API access and webhooks
Keep API keys on your server. Verify webhook signatures before trusting a delivery.
Contact
For security questions or deletion requests, contact Support. Don't include secret values.