Certified Execution Record (CER) Retention Policy

    1. Scope

    This policy describes how NexArt retains Certified Execution Records (CERs) generated or stored by NexArt-operated services.

    This policy applies only to CERs processed through NexArt-hosted infrastructure. It does not apply to CERs generated and stored solely by third parties using the open-source SDK.

    2. What Is Retained

    NexArt-operated services may retain:

    • CER bundles (cer.ai.execution.v1)
    • Associated attestation receipts
    • Minimal operational metadata required for system integrity and billing

    CER bundles are stored in secure cloud infrastructure operated by or on behalf of NexArt.

    No raw model prompts or outputs are retained unless explicitly included within a CER bundle by the caller.

    3. Retention Period

    By default, NexArt retains CER bundles and associated attestation receipts for 12 months from creation.

    Retention periods may vary depending on:

    • Contractual agreements
    • Project-specific retention policies
    • Legal, regulatory, or fraud-prevention requirements

    A minimum retention period of 90 days is enforced to support operational integrity and abuse detection.

    Retention policies are automatically enforced by NexArt systems across stored artifacts on a recurring schedule.

    NexArt does not guarantee indefinite hosting of CER bundles beyond the configured retention period. Users are strongly encouraged to export CER bundles for long-term storage and independent verification.

    Exported CER JSON files remain independently verifiable offline indefinitely using the public SDK.

    4. Portability

    CER bundles are portable JSON artifacts.

    Users may export CERs at any time. Exported artifacts remain verifiable offline without requiring access to NexArt infrastructure.

    Deletion of a CER from NexArt systems does not affect the verifiability of previously exported artifacts.

    5. Integrity Guarantees

    Once sealed, CER bundles are treated as immutable records.

    NexArt does not modify snapshot content, certificateHash values, or attestation receipts after issuance.

    If redaction is required, a new sealed record must be created.

    6. Deletion

    Users may request deletion of stored CERs, subject to:

    • Contractual obligations
    • Legal requirements
    • Fraud prevention or abuse investigation needs

    Deletion removes NexArt-hosted copies only. It does not affect user-exported copies.

    7. Policy Updates

    NexArt may update this policy from time to time. Material changes will be reflected by updating the "Last Updated" date below.

    Last Updated: 28 May 2026

    This policy describes NexArt's operational practices and does not constitute a contractual guarantee unless expressly incorporated into a written agreement.