What leaves your machines#
Astraeus is built so that your data stays on your machines, and Astralyx keeps only what it needs to schedule and show your work: specifications, states, metrics and totals. This page lists every class of data, where it lives, how long it is kept and how it is deleted, so you can answer a data protection review precisely.
The places data can be:
- Your machines: your servers, running the Astraeus agent.
- Kept by Astralyx: the Astralyx control plane (SaaS), which runs your cluster — Astraeus Cloud or a cluster dedicated to your organisation — and the console.
- Passes through Astralyx: carried from a machine to your browser or CLI when you ask for it, and not kept.
Data classes#
| Data | Lives on | What Astralyx keeps |
|---|---|---|
| Datasets, outputs, checkpoints (drives) | Your machines, under the data location chosen for each machine, or the paths you pinned | Only drive records: name, size hint, which machines hold a copy and its measured size. |
| Model weights | Your machines, in a drive the model manages; downloaded by a run on the machine (from Hugging Face at a pinned commit, or already in your drive) | Only the model record (source, files, sizes). |
Notebooks (.ipynb) |
Your machines, on a drive | The notebook record: title, drive and path. The notebook itself passes through, streamed, when you open or save it in the console; it is not kept. |
| Data source contents (files, schemas, profiles) | Your machines (the state of the agent's data part) | Totals only. Listings, partitions and profiles are read from the machine on request and pass through. |
| Credential values | Your secret manager; fetched by the machine that needs them, kept under its work root while a worker there uses them | Never. Only the reference and a sync status. |
| Run specifications (image, command, resources, environment variables, labels) | Kept by Astralyx | Yes: this is what is scheduled. |
| Agent run inputs and instructions (Anemoi) | Kept by Astralyx, in the run's specification; then on the machine | Yes. |
| Worker logs (standard output and error) | Your machines, in the container runtime; after a worker is removed, its last 1,000 lines in a file on the machine | No. They pass through when someone asks (an answer of at most about 900 KiB), held only until read — at most 60 seconds — then deleted. |
| Agent traces and activity (tool calls, model calls, connections) | Your machines | No, as for logs. Call counts per decision are reported (the latest 50 per worker). |
| Agent run receipts | Your machines, and kept by Astralyx | Digests of the specification, policies, input and output, totals (calls, tokens, cost), approvals; never arguments, URLs or answers. |
| Approvals | The held call's arguments stay on the machine | Target and digests of the call; who decided and why; the e-mail asking for a decision. |
| Evidence packs | Kept by Astralyx | Metadata and digests only; never prompts, answers, tool arguments or URL queries. |
| Prompts and answers to Eos deployments, through your edge gateway | Your machines | No. |
| Prompts and answers in the console's Playground | Your machines (the answer is kept in the worker's memory until read) | They pass through: each request and each piece of the answer is held until read, then deleted. A record of who asked and which replica answers is kept for 1 hour. |
| Prompts and answers through the hosted inference gateway (off unless a workspace admin turns it on) | Your machines | They pass through, whole, and are not kept; token counts are kept for usage. |
Metrics series (CPU, memory, disks, network, InfiniBand, GPUs, workers, drives; your workers' own app_ metrics) |
Machines spool them (up to 64 MiB, 90 minutes) until delivered | Yes. |
| Machine inventory (name, hostname, addresses, CPUs, memory, GPUs and their health, disks, labels, agent version) | Kept by Astralyx | Yes. |
| States and history of runs, workers, machines, drives, schedules, and the events derived from them | Kept by Astralyx | Yes. |
| Usage (GPU-, core-, GiB- and worker-seconds per workspace per hour) | Kept by Astralyx | Yes, priced for the usage pages. |
| Accounts (e-mail, name, password hash, sign-in links), sessions, API tokens (hashes) | Kept by Astralyx | Yes. |
| Organisations, workspaces, members, invitations, alert channels, event streams | Kept by Astralyx | Yes; secrets among them (SSO client secrets, webhook URLs, event stream credentials) are encrypted. |
| Audit records | Kept by Astralyx | Organisation changes, and requests made in a cluster with the user who made them. |
Names of objects (runs, drives, machines, workspaces) are visible wherever the object is. Do not put confidential information in names, labels or environment variables of a run: put secrets in Credentials.
Logs are read, not collected#
Astraeus does not ship your workers' logs anywhere. When you open a worker's
logs in the console, with astra logs or through the
API:
- Astraeus asks the machine running the worker, over the connection the machine opened.
- The machine reads the last lines from its container runtime (
tail, default 1,000, at most 10,000) and answers. - Astraeus hands the answer to you and deletes it. A request nobody answers expires.
The same path serves agent traces and activity, data source listings and profiles, and held approvals. If the machine is offline, there is nothing to read until it returns.
Retention#
| Data | Kept | Configurable |
|---|---|---|
| Metrics series | 30 days | No |
| Machines' metrics spool | Up to 64 MiB and 90 minutes, until delivered | No |
| Objects and their history (runs, workers, machines, drives) | Until the object is deleted | Delete the object |
| Usage buckets | 400 days | No |
| Workspace events | Kept | Per workspace: PUT /api/v1/orgs/<org>/workspaces/<ws>/events-retention {"days": N}. Events not yet sent to an event stream are never removed. |
| Organisation audit log | Kept | No |
| Logs on machines | As long as the container exists; the last 1,000 lines of a removed worker stay in a file on the machine | Remove the files on the machine |
| Agent traces, activity and receipt lines on machines | 7 days after the run leaves the machine | Workspace retention policy (machine_traces_days) |
| Finished agent runs, flow executions, evaluation runs | Kept | Workspace retention policy (runs_days) |
| Finished approvals | 7 days | Workspace retention policy (approvals_days) |
| Evidence packs | Kept | Workspace retention policy (evidence_packs_days) |
| Agent run receipts kept by Astralyx | Kept (at least 30 days, and at least as long as evidence packs) | Workspace retention policy (receipts_days) |
| Playground records | 1 hour | No |
| Expired sessions, sign-in states | Deleted when they expire; e-mail links, device codes a day after; API tokens 30 days after | No |
Retention policies are set per workspace by its admins; see Events and audit.
Deletion#
| You delete | What goes |
|---|---|
| A run | Its workers stop and their containers are removed from the machines. The last 1,000 log lines of each stay on its machine. Its record and history are deleted. |
| A drive placed by Astraeus | Every machine's copy. A drive over a path you pinned or shared never deletes that path: it was yours before it was a drive. |
| A model | The drive holding its weights, and so every copy. Weights in your own drive are never deleted. |
| A Credential | The reference. Machines remove the value once no worker needs it. |
| A workspace's access to a cluster | Every schedule, replica group, run, worker, endpoint, data source, drive and Credential of the workspace on that cluster. Agent run receipts are kept. |
| A machine (Remove) | Its record, subnet and reservations; its credentials are revoked. Its work is marked lost at once, so runs and replica groups replace it. Data on the machine stays there; install.sh --uninstall removes the agent from the machine. |
| Metrics series | They expire after 30 days; they cannot be deleted one by one. |