Keep evidence while minimizing exposed information
ENTITY's privacy layer separates evidence commitments from raw payloads. You can enforce purpose-bound use, retain commitments after payload destruction, preserve legal holds and keep sensitive provenance metadata encrypted.
1. Register a retention policy for a payload commitment
ledger = SelectiveRetentionLedger(STATE, identity)
record = ledger.register(
controller=owner_id,
subject_ref=object_id,
payload_sha256=PAYLOAD_SHA256,
purpose="RESEARCH",
jurisdiction="CA",
retain_until_ms=RETENTION_END,
destruction_mode="DELETE_PAYLOAD",
)The ledger records the commitment and policy state, not the raw payload.
2. Test legal/temporal controls
Destruction before retain_until_ms must fail. A LEGAL_HOLD record must refuse destruction even after the nominal retention period.
3. Destroy with evidence
destroyed = ledger.destroy(
owner_id,
record["record_id"],
destruction_evidence_sha256=DESTRUCTION_EVIDENCE_SHA256,
at_ms=AFTER_RETENTION,
)The resulting state preserves the original payload commitment and the destruction-evidence commitment while marking the governed record destroyed.
4. Use confidential provenance when public lineage is too revealing
private_graph = ConfidentialProvenanceLedger(STATE, identity)
edge = private_graph.add_edge(
actor=owner_id,
parent_ref=source_ref,
child_ref=derived_ref,
relationship="DERIVED_FROM",
evidence_sha256=EVIDENCE_SHA256,
metadata={"internal_method":"restricted"},
encryption_key=KEY,
)The public record can retain a metadata commitment while sensitive metadata remains AES-GCM protected. Later disclosure can prove the revealed metadata matches the original commitment.
5. Distinguish local and remote deletion
A local erase does not prove a provider erased its copy. A remote deletion request does not prove fulfillment. A remote deletion attestation is evidence from the attestor and should be evaluated under the applicable trust policy.