Back to updates
UpdatedAug 10, 2026

Nullify — Updated!

Automated, policy-driven data retention and deletion system with immutable audit trails, RBAC/ABAC, multi-jurisdiction compliance, and AI/ML classification for sensitive data.

Share

Nullify

Secure. Transparent. Nullified.

Nullify is an open source, modular data retention, deletion, and lifecycle governance platform. It provides a centralized framework for discovering data, evaluating retention policies, executing controlled lifecycle actions, and maintaining verifiable audit records across distributed data environments.

Nullify is designed around a specification-first architecture. Core modules provide the foundational capabilities required for data lifecycle governance, while optional plugin modules extend Nullify with additional connectors, compliance frameworks, intelligence, integrations, storage systems, and deployment capabilities.

Specification

Nullify defines an open source architecture for centralized data lifecycle management.

The specification is built around several principles:

  • Centralized policy coordination
  • Distributed data source support
  • Policy-driven retention and deletion
  • Explicit authorization and approval
  • Dry-run and validation workflows
  • Immutable and verifiable auditing
  • Data lineage and provenance
  • Modular connectors and integrations
  • Human oversight for destructive operations
  • Secure-by-default execution
  • Vendor-neutral architecture
  • Local, cloud, hybrid, and federated deployment
  • Extensible plugin architecture
  • Transparent policy evaluation
  • Reproducible lifecycle decisions

Nullify does not require organizations to migrate their data into a proprietary centralized repository. Instead, the system coordinates lifecycle policies and actions across existing data environments.

Architecture

Nullify is divided into two primary architectural layers:

  1. Core Modules
  2. Optional Plugin Modules

Core modules contain the foundational functionality required to operate Nullify. Optional plugins provide specialized functionality without making the base platform dependent on a particular database, cloud provider, compliance framework, AI system, notification platform, or infrastructure environment.

Core Architecture

The primary lifecycle flow is:

Discovery → Classification → Policy Evaluation → Approval → Scheduling → Execution → Verification → Audit

Each stage is represented by an independently maintainable core module.

Core Modules

1. Data Discovery Module

The Data Discovery Module identifies and inventories data resources managed by Nullify.

Features include:

  • Data source registration
  • Resource discovery
  • Dataset and object inventories
  • Metadata collection
  • Data ownership metadata
  • Creation and modification timestamps
  • Access metadata
  • Storage location tracking
  • Resource status tracking
  • Data source health monitoring
  • Discovery scheduling

The module provides the inventory required by downstream lifecycle policies without requiring the underlying data to be copied into Nullify.

2. Data Classification Module

The Data Classification Module assigns structured metadata to discovered resources.

Features include:

  • Data category assignment
  • Sensitivity classification
  • PII classification
  • Financial data classification
  • Health data classification
  • Internal and public classification
  • User-defined classifications
  • Classification confidence
  • Classification history
  • Manual classification
  • Classification overrides

Classification results become inputs to the policy evaluation process.

3. Policy Engine Module

The Policy Engine is the central decision-making component of Nullify.

Features include:

  • Retention policies
  • Deletion policies
  • Archival policies
  • Anonymization policies
  • Legal hold rules
  • Exception rules
  • Policy priorities
  • Policy inheritance
  • Policy versioning
  • Policy activation and expiration
  • Policy simulation
  • Policy conflict detection
  • Policy validation
  • Policy rollback

Policies should be declarative and machine-readable.

Nullify should support multiple policy formats while maintaining a normalized internal policy model.

4. Lifecycle Decision Module

The Lifecycle Decision Module converts policy evaluations into explicit lifecycle decisions.

Supported decisions include:

  • Retain
  • Review
  • Archive
  • Anonymize
  • Delete
  • Legal hold
  • Exception
  • Defer

Every decision should contain sufficient metadata to explain:

  • What decision was made
  • Which resource was affected
  • Which policy produced the decision
  • Which policy version was used
  • When the decision was created
  • When the decision should be executed
  • Whether approval is required

5. Approval and Human Oversight Module

Nullify should not assume that every destructive operation can be fully automated.

The Approval Module provides controlled human oversight.

Features include:

  • Approval queues
  • Multi-person approval
  • Role-based approval
  • Approval delegation
  • Approval expiration
  • Rejection workflows
  • Escalation workflows
  • Emergency holds
  • Manual overrides
  • Approval history

Organizations can configure which actions require human approval and which may execute automatically.

6. Scheduling Module

The Scheduling Module manages when lifecycle actions occur.

Features include:

  • Scheduled deletion
  • Scheduled archival
  • Scheduled anonymization
  • Batch processing
  • Priority queues
  • Maintenance windows
  • Resource-aware scheduling
  • Retry scheduling
  • Dependency-aware execution
  • Workload balancing
  • Execution throttling

Scheduling should separate the decision to perform an action from the actual execution of that action.

7. Action Execution Module

The Action Execution Module performs approved lifecycle operations against registered data sources.

Supported lifecycle actions include:

  • Delete
  • Archive
  • Anonymize
  • Redact
  • Quarantine
  • Move
  • Expire
  • Revoke access

Features include:

  • Dry-run execution
  • Pre-execution validation
  • Execution confirmation
  • Transaction-aware operations where supported
  • Retry handling
  • Failure detection
  • Partial failure tracking
  • Execution status
  • Execution receipts
  • Idempotent execution
  • Safe execution controls

Destructive actions should require explicit authorization according to configured policy.

8. Verification Module

The Verification Module confirms whether lifecycle actions were successfully completed.

Features include:

  • Deletion verification
  • Archive verification
  • Anonymization verification
  • Source confirmation
  • Replica verification
  • Retry verification
  • Failed-action detection
  • Residual data detection
  • Verification reports

Verification should distinguish between:

  • Requested
  • Authorized
  • Scheduled
  • Executed
  • Verified
  • Failed
  • Partially completed

9. Audit and Evidence Module

The Audit and Evidence Module records the complete lifecycle of every important system action.

Features include:

  • Immutable audit events
  • Cryptographic event integrity
  • Policy decision records
  • Approval records
  • Execution records
  • Verification records
  • User activity records
  • Configuration history
  • Policy history
  • Audit export
  • Evidence packages
  • Chain-of-custody records

Audit records should make it possible to reconstruct why a lifecycle decision occurred and what happened afterward.

10. Data Lineage Module

The Data Lineage Module tracks relationships between data resources.

Features include:

  • Source lineage
  • Destination lineage
  • Transformation lineage
  • Copy relationships
  • Replication relationships
  • Derived-data relationships
  • Parent-child relationships
  • Data movement history
  • Lifecycle propagation

Lineage allows Nullify to identify related resources that may also require retention, archival, anonymization, or deletion.

11. Access Control Module

The Access Control Module protects administrative and lifecycle operations.

Features include:

  • Role-Based Access Control
  • Attribute-Based Access Control
  • Permission management
  • Resource-level permissions
  • Action-level permissions
  • Approval permissions
  • Administrative separation
  • Session management
  • Authentication integration
  • Authorization auditing

Categories