← back to coldcache

How Coldcache Handles Your Data

Plain-language operating policy for the validation phase

Version 2.1 · 24 July 2026

Short version

Coldcache asks for the minimum data required for the audit level you choose. Raw files are processed locally by default, stored on an encrypted device in a dedicated client folder, and deleted from systems under Coldcache’s control within seven calendar days after final delivery.

Raw client files are not uploaded to consumer AI chat products. If an external processor is needed, the specific provider, purpose, account type, relevant retention setting, and applicable terms are disclosed before use.

1. The data depends on the service

ServiceTypical data requestedWhat that data supports
Metadata Cost ScanOpenAI or Anthropic usage and cost export: model, tokens, cost, time period, project/workspace, cache and service-tier fields where available.Model mix, cost concentration, token trends, cache use, time-based anomalies and broad batch opportunities. It cannot reliably identify a specific n8n root cause.
Execution-Level Cost AuditProvider data plus n8n execution IDs, workflow/node labels, timestamps, status, retry/error fields, latency, schedules, traces and sanitized configuration where necessary.Duplicate executions, retry-related spend, excessive schedules, costly nodes, failed calls, agent loops and workflow-level attribution where records can be correlated.
Implementation SprintOnly the sanitized workflow configuration, test cases and access needed for the agreed changes.Testing and applying a limited number of approved fixes. Production credentials are not requested by default and rollout remains client-controlled.
Cost Regression MonitorOnly the ongoing telemetry and alerts agreed in the statement of work.Changes in cost per workflow or successful execution, retry/failure costs, cache deterioration and regressions after deployments.

2. What Coldcache does not want

Never send by default

  • API keys, passwords, access tokens or production credentials
  • personal data, customer records or regulated records
  • privileged legal material or safety-critical data

Keep outside the scope

  • full production databases or unrelated source repositories
  • unnecessary raw prompts, responses or customer messages
  • information you do not have the right to share

If Coldcache receives obvious secrets or unnecessary personal data, processing stops. The file is rejected or securely deleted, and a sanitized replacement is requested.

3. What different data sources can prove

Data source can usually showIt cannot prove by itself
Provider exports: model use, token totals, cost, cache fields, time periods, projects/workspaces and service tiers.Which n8n node caused the cost, whether a call was necessary, or whether the answer was correct.
n8n execution data: workflow runs, node path, status, duration, retries and errors.Exact provider cost unless calls are correlated or cost is attached to the execution.
LiteLLM, Helicone, LangSmith or similar traces: request-level model, latency, tokens, cost, errors, sessions and tags where configured.Whether the final business outcome was correct or valuable without test cases or client context.
Sanitized workflow configuration: schedules, branches, model settings, tools, limits and retry logic.How often production actually ran, how much it cost, or whether outputs were used.
Representative test cases: whether a proposed cheaper configuration preserves acceptable output.Historical production spend or how often the problem occurred.

4. How files move through Coldcache

  1. Scope first. Before files are shared, Coldcache confirms the audit level, required fields, exclusions, transfer method, and expected deliverables.
  2. Client redaction. The client removes credentials, personal data, and material outside scope using the intake and redaction checklist.
  3. Secure transfer. The transfer method is agreed before the engagement. Coldcache will not ask the client to paste raw logs into a consumer AI chat.
  4. Second intake check. Coldcache checks for obvious secrets, personal data, and missing fields. Unsafe or unsuitable files are rejected.
  5. Local analysis. Aggregation, pricing, anomaly detection, correlation, and report tables are produced with deterministic local tools where practical.
  6. Delivery and deletion. The report is delivered, raw files are deleted on schedule, and a deletion checklist is completed.

5. Storage and account security

ENCRYPTED DEVICE

Full-disk protection

Client files are stored on a computer protected by full-disk encryption.

CLIENT SEPARATION

Dedicated folders

Each engagement has separate raw, sanitized, analysis, report, and deletion records.

NO CLOUD SYNC BY DEFAULT

Controlled storage

Raw folders are not intentionally placed in personal Dropbox, Google Drive, iCloud, or OneDrive sync locations unless approved and disclosed.

ACCOUNT SECURITY

Unique passwords and MFA

Business accounts use separate strong passwords and multi-factor authentication where available.

LEAST PRIVILEGE

Exports before admin access

Coldcache requests exports rather than administrator access and avoids production credentials.

PATCHED SYSTEMS

No shared client logins

The operating system and analysis tools are kept updated, and client work is not performed through shared accounts.

6. Use of LLMs and other service providers

Raw client files are not uploaded to consumer AI chats. If LLM assistance adds value, the default input is limited to redacted derived metrics or de-identified summaries — for example, provider, model-cost share, average token size, retry rate, and anonymous workflow labels, without prompts, customer messages, credentials, or personal data.

Any external processor, including a commercial/API LLM service, secure file-transfer provider, e-signature provider, scheduler, or payment service, is disclosed in the engagement documentation with its purpose, account type, relevant retention setting, and applicable terms. If the client does not approve, the parties may use a client-managed environment, local-only processing, a narrower scan, or decline the affected work.

Coldcache does not use client data to train or fine-tune models. Provider retention and training behavior depends on the exact product, account, and settings, so Coldcache does not promise deletion from an external system unless that behavior has been verified and documented.

7. Retention and deletion

Data categoryValidation-phase treatment
Raw provider exports, n8n logs, traces and sanitized configurationDeleted from systems under Coldcache’s control within seven calendar days after final delivery, or earlier on written request, unless another period is agreed.
Final report and ordinary business recordsMay be retained for support, invoicing, accounting, tax, legal or dispute purposes. These records should not contain unnecessary raw logs.
Case-study dataRetained only with separate written permission and only in the approved anonymized or identified form.
External-processor dataSubject to the disclosed processor terms and settings. Retention is addressed explicitly rather than assumed.
Deletion evidenceA deletion checklist is completed and written confirmation is available on request.

8. Implementation and production systems

An audit does not require production credentials. An Implementation Sprint is separately scoped and limited. No live change is made without a rollback plan, and the client controls production deployment unless a separate signed agreement says otherwise.

9. Case studies and publicity

Nothing about a client, project, finding, or savings result is published without separate explicit written approval. The client may approve a specific draft, approve anonymized publication only, or refuse publication entirely. “Anonymized” does not mean “automatically safe”; details are reviewed with the client before publication.

10. Client-managed and local-only options

Where practical, the client may run a supplied local analysis step or use its own approved environment and share only structured findings. This reduces data movement but may require more setup and may limit audit depth.

11. Incidents and requests

If Coldcache suspects unauthorized access or mishandling, processing stops, necessary evidence is preserved, the affected client is notified promptly, relevant credentials are rotated where applicable, and corrective action is documented. Clients may request early deletion, ask which processors are being used, or request a copy of the deletion confirmation.

12. Scope exclusions during validation

Coldcache does not accept regulated or safety-critical engagements during validation. This includes raw healthcare records, regulated financial or payment data, privileged legal material, or workflows where testing could create material real-world harm. EU engagements involving personal data are deferred until a reusable data-processing agreement and documented process are ready.

13. Want an NDA before sharing anything?

That is completely fine. Coldcache can provide a mutual NDA before you send logs, exports, workflow files, or other project information. You are not required to share any data before the NDA is signed.

Email an NDA request

14. Contact

Questions before sharing data: hello@coldcache.ai
Website: coldcache.ai
Operator: Aleksandr Globenko, operating as Coldcache

This page explains Coldcache’s validation-phase operating practice in plain language. A signed NDA, statement of work, and any applicable data-processing agreement control if there is a conflict. This document is not a security certification, legal advice, or a substitute for client-side compliance review.