Customer systems remain the sources of truth.
Customer systems stay authoritative. SupraOS processes the operating state required to coordinate, execute and prove approved work from customer-approved sources.
Effective and last reviewed: 16 July 2026
What stays in customer systems
Customer CRM, product, support, contract, finance, identity, work, and evidence systems remain the systems of record. SupraOS stores the scoped state required to coordinate and prove the approved workflow.
Source boundaries and coverage
Revenue and customer sources
CRM, account, renewal, product-usage, support, contract, and finance sources approved for the deployment.
Operational sources
Work queues, tickets, incident, procurement, supplier, field-service, inventory, and internal data sources approved for the workflow.
Evidence sources
Documents, files, logs, attestations, approvals, and customer-provided artifacts used to support a decision or verify an outcome.
Connected
The source and approved objects are available within the current scope.
Limited or pending
Access is partial, field-limited, awaiting customer action, or not yet validated.
Unavailable or blind
Coverage gaps remain visible throughout the run.
Every evidence type keeps its source, provenance and confidence label. Confidence does not replace evidence.
What SupraOS stores
| Category | Purpose |
|---|---|
| Approved recovery scope and work state | Define the objective, owners, source scope, authority, approval state, and current execution stage. |
| Evidence references and selected artifacts | Support decisions, approvals, verification, and outcome proof where required. |
| Policy and approval events | Show why an action was permitted, held, or blocked and who approved it. |
| Execution and verification metadata | Record the action, connector context, destination-system response, and read-back result. |
| Action Receipts and Value Ledger records | Preserve outcome proof and clearly labeled value states. |
Data path
Data minimization and location
Minimize collection
SupraOS processes the minimum data required to run, secure, support and prove the approved work.
Managed hosting in Europe
SupraOS runs its managed service on European infrastructure. Security diligence covers every provider, processing location and transfer safeguard.
Customer instructions control the deployment
The signed agreement, DPA, security schedule, order form, and deployment documentation define the actual scope.
Retention, deletion and portability
Product retention
Product retention, return, deletion, audit, and legal-hold rules are defined in the applicable customer agreement and deployment schedule.
Website analytics
With analytics consent, raw full IP addresses are removed no later than 30 days after collection. Analytics events are removed no later than 365 days after collection.
Consent record
The cookie-choice record lasts 180 days unless the visitor changes the choice or clears cookies.
Export and deletion requests
Customer export and deletion obligations follow the DPA and deployment documentation. Website privacy requests go to privacy@supraos.co.
Training use
SupraOS never uses customer data to train a model shared across customers. Every enabled model provider is disclosed before use.