Retention Settings for PII Files in Thru


Issue

The configuring retention settings for files processed through the Thru Managed File Transfer (MFT) system, specifically regarding the retention of decrypted Personally Identifiable Information (PII) files. The primary concern is that while the global retention schedule is set to purge files immediately (0 days), the system requires a minimum retention period for errored files, preventing the immediate deletion of decrypted PII files.

Cause

The issue arises from the design of the Thru MFT system's retention policies. The Purge Immediately feature is intended to clear files after successful deliveries. However, for files that encounter errors during transfer, the system mandates a minimum retention period of 1 day. This policy is in place to prevent the accidental loss of files during temporary network outages, allowing time for retries. As a result, errored files remain in the Thru storage location for at least one day, which poses a risk for retaining decrypted PII data.

Additionally, the use of the Thru Cloud repository complicates matters, as files that fail to transfer remain at rest until the configured retention period expires. This situation necessitates alternative strategies to manage the retention of sensitive data effectively.

Resolution

To address the retention issues for decrypted PII files in the Thru system, consider the following approaches:

  1. Re-encrypt Files Immediately: Implement a process to re-encrypt files immediately after processing, before they are written to any intermediate storage locations.

  2. Error-Handling Logic: Develop error-handling logic within the Boomi process to automatically delete files if the transfer to the target fails. This can help minimize the risk of retaining decrypted files.

  3. In-Memory Processing: Where feasible, process files in memory to avoid writing decrypted files to disk. This approach can significantly reduce the risk of exposing sensitive data.

  4. Thru Node Direct: Switch to using Thru Node Direct for file transfers. This method allows decryption and transfer to occur locally on the Node's temporary storage, bypassing the Boomi MFT Cloud. If a transfer fails, the temporary local files can be purged immediately, eliminating the need for retention policies that apply to cloud-stored files.

  5. Configure Retention Settings: Set the lowest possible retention value allowed by the platform for successful files to reduce the time files remain in storage.