ENTITY Documentation Portal
Core tutorial 9

Keep evidence while minimizing exposed information

ENTITY's privacy layer separates evidence commitments from raw payloads. You can enforce purpose-bound use, retain commitments after payload destruction, preserve legal holds and keep sensitive provenance metadata encrypted.

1. Register a retention policy for a payload commitment

ledger = SelectiveRetentionLedger(STATE, identity)
record = ledger.register(
    controller=owner_id,
    subject_ref=object_id,
    payload_sha256=PAYLOAD_SHA256,
    purpose="RESEARCH",
    jurisdiction="CA",
    retain_until_ms=RETENTION_END,
    destruction_mode="DELETE_PAYLOAD",
)

The ledger records the commitment and policy state, not the raw payload.

2. Test legal/temporal controls

Destruction before retain_until_ms must fail. A LEGAL_HOLD record must refuse destruction even after the nominal retention period.

3. Destroy with evidence

destroyed = ledger.destroy(
    owner_id,
    record["record_id"],
    destruction_evidence_sha256=DESTRUCTION_EVIDENCE_SHA256,
    at_ms=AFTER_RETENTION,
)

The resulting state preserves the original payload commitment and the destruction-evidence commitment while marking the governed record destroyed.

4. Use confidential provenance when public lineage is too revealing

private_graph = ConfidentialProvenanceLedger(STATE, identity)
edge = private_graph.add_edge(
    actor=owner_id,
    parent_ref=source_ref,
    child_ref=derived_ref,
    relationship="DERIVED_FROM",
    evidence_sha256=EVIDENCE_SHA256,
    metadata={"internal_method":"restricted"},
    encryption_key=KEY,
)

The public record can retain a metadata commitment while sensitive metadata remains AES-GCM protected. Later disclosure can prove the revealed metadata matches the original commitment.

5. Distinguish local and remote deletion

A local erase does not prove a provider erased its copy. A remote deletion request does not prove fulfillment. A remote deletion attestation is evidence from the attestor and should be evaluated under the applicable trust policy.

Privacy is not “delete the audit trail.” ENTITY is designed so the system can preserve signed commitments/evidence while minimizing or destroying payloads according to explicit rules.