The week afterscene 9 / 15~3 min
What we keep
Friday opens with a compliment and closes with an inventory.
Friday, the audit’s last day, opens with a compliment, which from auditors is rare enough to note in the minutes.
The subject is race week’s Wednesday. A library Traversal depends on had shipped a vulnerable dependencyConcept · lights on your mapvulnerable dependencyA security hole in code you borrowed: one of the hundreds of packages underneath your product. When one is disclosed, with a CVE number, every product using it inherits the hole overnight, and attackers scan for laggards within hours. The defence is automated dependency scanning in the pipeline, fast patching, and knowing what you run. The industry’s biggest breaches increasingly start here., and the auditors walk the timeline with growing approval. Advisory public at 8:12. Patch decided by two people with the authority to decide it, tiny diff, every gate passed, canary first, everywhere by 3:40, rollback plan written before anyone touched a thing. Mid-freeze. The report’s phrasing is dry, and underneath the dryness it says the thing every team wants said. When the world handed this company a hole, it was closed within a working day, on the record.
The central question
Then the lead auditor opens a fresh page and asks it. What, exactly, does Traversal hold about 25,000 finishers? The list is longer than anyone in the room enjoys hearing read aloud. Names, emails, birthdates, emergency contacts, card records at Ledgerline, medical notes from the race-day waiver, GPS breadcrumbs, and a million photographs stamped with place and minute. Most of it is personally identifiable informationConcept · lights on your mappersonally identifiable informationInformation that identifies a person directly or can reasonably be connected to one: name, email, phone, birthdate, government ID, account and device identifiers, precise location, financial details. The label changes obligations: who may see the data, where it may live, and which laws apply to it., PII on every following page of the report, and the label is a verdict. Data with obligations attached.
The second half of the question is for how long, and the honest answer needs a policy, and the policy has a name: data retentionConcept · lights on your mapdata retentionDeciding how long information is kept, and when it is deleted. Never “everything forever”: a deliberate policy connecting business need, customer expectation, law, security, and cost, with different periods for different data, from logs kept days to financial records kept legally required years, plus honouring deletion requests when a person asks.. Results are the product, kept for the decade Traversal is proud of. Payment records live at Ledgerline under finance’s clock. And the GPS trails and the photo pile’s metadata get the report’s sharpest line: data that can place a person on a map at a minute deserves a deletion date, and today it does not have one. Every byte you keep is a byte someone can steal, subpoena, or leak. Keeping less is the one security control that cannot fail.
One question near the end sounds like a trap and is not. What does the test world hold? Act II’s answer still stands: invented runners, plausible fakes, nothing worth stealing. The auditors check anyway, pull one staging record, watch it resolve to a runner who has never existed, and write the shortest line in the report. Nothing to protect here, kept that way on purpose.
The lanyards come off at five. Findings: two ghost roles, one missing deletion date, and a paragraph of praise. And one line of the inventory refuses to leave Finn’s head over the weekend, ten years of race history, kept on purpose, feeding something this story keeps mentioning and has never once explained. On Monday, Dana walks in holding the reason.
End of scene
This scene covers: vulnerable dependency, personally identifiable information, data retention