Inventory
| What | Where it is stored | Who can read it | How to delete it |
|---|---|---|---|
| The Agent Card you point Suncly at | The evidence store (files under ~/.suncly/store, or your Postgres) | Whoever can read that store | Remove the files or drop the database |
| The test plan and its approval (contract, test cases, approved_by) | The evidence store | Whoever can read that store | Remove the files or drop the database |
| Redacted transcripts of every run | ~/.suncly/transcripts on the machine that ran it | Whoever can read that folder | Remove the files |
| Your agent credential | Only the Runner process, from one environment variable; never written | Nobody; it is redacted from every transcript | Unset the variable |
| The deployment signing key | ~/.suncly/keys | Whoever can read that folder | Delete the key; earlier reports still verify with the public key in result.json |
| Report folders | ./suncly-reports/<attestation-id>/ | Whoever you give them to | Delete the folder |
Anatomy of a report folder
| File | Contents |
|---|---|
report.html | The report for a reviewer. Self-contained; opens offline. |
report.md | The same content as Markdown. |
result.json | The evidence bundle: attestation, runs, decisions, card version, contract, results, the signed payload and the public key. |
transcripts/<run-id>.json | One redacted transcript per run, with its Layer 1 checks. |
Deletion, truthfully
The evidence store is append-only by design: run and decision records are never updated or deleted by the software. You delete by removing files or dropping the database. For a hosted service, append-only evidence and erasure requests will need a documented answer; that question is open and recorded in HANDOFF.md.
What changes when the hosted API arrives
- Evidence for hosted evaluations would be stored by Suncly, under a data processing agreement, with a published sub-processor list.
- Accounts and API keys would exist; the Privacy Policy's hosted sections switch on then.
- The Runner is designed to run inside your network later, so credentials can stay there.
Verified against src/suncly on 2026-10-05. The security page covers credentials, redaction and the non-negotiable rules: /security. The Privacy Policy covers this website: /privacy.
