Deletion and erasure
Deletion kinds
Section titled “Deletion kinds”| Kind | Scope |
|---|---|
record |
All versions of an id |
author |
Every record of one owner (a person, account, customer or device) |
record_before |
Versions older than a batch sequence |
batch |
A whole batch |
Ids become HMAC pseudonyms on arrival. The request enters the tenant’s ledger in one transaction.
What happens at once
Section titled “What happens at once”As soon as the request is in the ledger, the records vanish from the change feed, exports and point reads. Later uploads of deleted ids are filtered.
The weekly roll
Section titled “The weekly roll”By default a new epoch opens every seven days: new keys are generated in both custodians and every key block is re-sealed under fresh data keys without the deleted record keys. An independent verification step checks the result before any key is destroyed. An operator can request an early roll.
Destruction and certificate
Section titled “Destruction and certificate”The old epoch waits out the seven-day safety window; the roll interval can never undercut it. Then its keys are destroyed in both HSMs, signed destruction evidence is stored, an erasure certificate is issued and an erasure.completed event enters the change feed.
The ciphertext is never rewritten; it becomes unreadable because no key opens it. Cryptographic erasure is a purge technique in NIST SP 800-88 Rev. 2; call it standards-based sanitisation.
Verifying the certificate
Section titled “Verifying the certificate”The certificate is a JWS signed by the receipts key. It names the tenant, the erased_through position, the destruction evidence and lost_epochs (epochs whose keys were closed by an approved loss declaration).
reindeerctl audit keysreindeerctl audit erasures -pin <receipts key>Without -pin the tools only show agreement with keys the same server presented. The console runs the same check in the browser.
Deletions that need approval
Section titled “Deletions that need approval”Batch deletions and deletions above the 24-hour limits wait for a second person, then a 24-hour cool-off that any approver may cancel. A key the journal expects but the HSM lacks is reported missing, never counted as destroyed, and closed only by an approved loss declaration.