Skip to content

Deletion and erasure

Kind Scope
record All versions of an id
author Every record of one owner (a person, account, customer or device)
record_before Versions older than a batch sequence
batch A whole batch

Ids become HMAC pseudonyms on arrival. The request enters the tenant’s ledger in one transaction.

As soon as the request is in the ledger, the records vanish from the change feed, exports and point reads. Later uploads of deleted ids are filtered.

By default a new epoch opens every seven days: new keys are generated in both custodians and every key block is re-sealed under fresh data keys without the deleted record keys. An independent verification step checks the result before any key is destroyed. An operator can request an early roll.

The old epoch waits out the seven-day safety window; the roll interval can never undercut it. Then its keys are destroyed in both HSMs, signed destruction evidence is stored, an erasure certificate is issued and an erasure.completed event enters the change feed.

The ciphertext is never rewritten; it becomes unreadable because no key opens it. Cryptographic erasure is a purge technique in NIST SP 800-88 Rev. 2; call it standards-based sanitisation.

The certificate is a JWS signed by the receipts key. It names the tenant, the erased_through position, the destruction evidence and lost_epochs (epochs whose keys were closed by an approved loss declaration).

Terminal window
reindeerctl audit keys
reindeerctl audit erasures -pin <receipts key>

Without -pin the tools only show agreement with keys the same server presented. The console runs the same check in the browser.

Batch deletions and deletions above the 24-hour limits wait for a second person, then a 24-hour cool-off that any approver may cancel. A key the journal expects but the HSM lacks is reported missing, never counted as destroyed, and closed only by an approved loss declaration.