KlaritiQKlaritiQ
Features

Inside the Evidence Locker: How KlaritiQ Stores and Protects Your Documents

KlaritiQ Team·August 2026·5 min read

When you upload a document to KlaritiQ as evidence - a policy, a contract, a vendor assessment, an audit report - two things happen. The document is read and the relevant facts are extracted into your readiness record, and, depending on your organization's settings, the original file itself can be kept in secure storage so it's available to open again later. This article covers that second part: where a retained document actually lives, and what protects it while it's there.

Extraction first, storage second

Every upload goes through the same first step regardless of settings: KlaritiQ reads the document and pulls out the specific facts, claims, and figures it supports. That extracted record is what your AI Readiness Index and evidence trail are actually built on - see Evidence: Why Nothing in KlaritiQ Is True Without It for how that works. Keeping the original file afterward is a separate, additional step on top of that, not a requirement for the score itself.

Document retention is opt-in, not automatic

By default, once a document has been read and its facts extracted, the original file is deleted and only the extracted evidence record remains. Storing the source file itself - so it can be reopened, downloaded, or shown to an auditor later - is a setting an organization's owner or admin has to turn on deliberately. We built it this way because keeping a client's own HR, legal, or vendor documents indefinitely is a real decision for that organization to make, not something that should happen by default without anyone choosing it.

Where a retained document actually lives

Retained files are stored in dedicated, enterprise-grade cloud object storage built specifically for file storage - the same category of infrastructure used across the software industry for this purpose, distinct from and separate from the database that holds your scores, decisions, and records. This separation matters for a practical reason: storing large files directly inside a database is slow and expensive to back up; dedicated object storage is built for exactly this job and scales accordingly.

Encrypted at rest

Every document stored this way is encrypted at rest using industry-standard AES-256 encryption, the same encryption standard used by major banks and cloud providers globally. This applies automatically to every file - it isn't a setting you need to enable separately.

A storage limit that scales with your plan

Retention isn't unlimited storage by default - each plan tier comes with a storage allowance for retained documents, so cost stays predictable as your usage grows. If your organization is near its limit, newly confirmed documents fall back to extraction-only (the file is deleted after its facts are captured, exactly like the default behavior) rather than the feature failing or your bill growing unexpectedly. You can see your current usage against your limit any time from the Evidence page.

Documents don't stay forever

Retained files are kept for a set period - one year by default - after which the original file is automatically and permanently removed. The extracted evidence record itself is never affected by this and remains in your readiness history permanently; only the original source file expires. This mirrors a principle we apply everywhere in KlaritiQ: don't hold onto raw source material longer than there's a real reason to, which matters in particular for organizations with their own data retention obligations to their own customers.

File-type verification on every upload

Every file uploaded to KlaritiQ is checked twice before it's accepted: once against a fixed list of allowed formats (PDF, PNG, JPEG, WebP, GIF, plain text, Markdown, and CSV - nothing else is accepted), and a second time to confirm the file's actual contents genuinely match the format it claims to be, not just its file extension or label. This catches a file that's been mislabeled or corrupted, or disguised as something it isn't. It's one layer of protection among several, not a substitute for only ever uploading files from sources you trust.

Downloading a retained document

If your organization has retention turned on and a document is still within its retention window, you can download the original file directly from that document's entry on the Evidence page - the same access level as viewing the evidence itself, available to any active member of your organization.

The short version

Extraction happens for every document, always, and is what your score is built on. Keeping the original file afterward is optional, encrypted at rest, capped to a sensible limit for your plan, automatically expired after a year, and checked for consistency on the way in. Nothing about this changes if your organization simply doesn't turn retention on - the extraction-only behavior is exactly what KlaritiQ has always done.

See where your own organization's evidence gaps actually are.See how evidence works in KlaritiQ

Was this article helpful?

Community Questions (0)

No questions yet. Be the first to ask!

Still have questions?

Contact support