Codapult
DocsBlogPricingPluginsDemo
Get Codapult
Logo

Build your SaaS with AI. Keep the architecture under control.

Get Codapult

Product

  • Pricing
  • Architecture
  • Modules
  • AI platform
  • Plugins

Developers

  • MCP
  • CLI
  • Documentation
  • Launch your SaaS
  • Build a B2B SaaS

Resources

  • Blog
  • FAQ

Connect

  • Contact
  • GitHub

Compare

  • SaaS template comparison
  • Codapult vs Supastarter
  • Codapult vs Makerkit
  • Codapult vs ShipFast
  • Codapult vs SaaSBold
  • Codapult vs Gravity
  • Codapult vs Nextbase
  • Codapult vs BuilderKit

Featured on

Codapult on LaunchNestCodapult on LaunchNestbetterlaunch.cobetterlaunch.coFeatured on LaunchBuffFeatured on LaunchBuffCodapult on PeerPushCodapult on PeerPushFeatured on LaunchItFeatured on LaunchIt
© 2026 Codapult·All rights reserved·Privacy Policy·Terms of Service
Full source code · One-time purchase · Self-host anywhere
All articles

Getting Started

  • Introduction
  • Quick Start
  • Your First 30 Minutes
  • Project Structure
  • License and Permitted Use
  • Starter Profiles and Recipes
  • Product Recipes

Configuration

  • Environment Variables
  • App Configuration
  • Which Modules Should I Enable?
  • Provider Matrix
  • Capability Coverage

Database

  • Database and Provider Guide
  • Database
  • Migrations

Authentication

  • Authentication
  • OAuth Providers
  • Two-Factor & Passwordless
  • Enterprise SSO (SAML)

Ai

  • AI Runtime Architecture and Evals
  • AI Features
  • Streaming Chat
  • RAG and Semantic Search
  • Quotas and Memory

Teams

  • Teams & Organizations
  • Permissions & RBAC
  • SCIM Provisioning

Security

  • Data Retention Policy
  • Security

Deployment

  • Enterprise E2E Evidence
  • Enterprise Production Readiness
  • Deployment, Backup, and Restore Runbook
  • Deployment
  • Troubleshooting

Payments

  • Payments & Billing
  • Stripe Setup
  • LemonSqueezy Setup
  • Polar Setup
  • Payment Webhooks

Api

  • API Layer
  • tRPC
  • GraphQL

Email

  • Email
  • Email Templates

Infrastructure

  • Infrastructure
  • Self-Hosting
  • File Storage
  • Docker
  • Background Jobs
  • Terraform & Pulumi
  • Kubernetes

Ui

  • UI & Theming

I18n

  • Internationalization

Content Management

  • Content Management

Admin

  • Admin Panel

Monitoring

  • Analytics & Monitoring

Modules

  • Module Architecture
  • Waitlist
  • Audit Log
  • White-Labeling
  • Workflow Automation
  • A/B Testing
  • Welcome Page
  • Referrals
  • GDPR Export and Deletion
  • Promotions
  • Outgoing Webhooks

Plugins

  • Plugin System
  • CRM Plugin
  • Helpdesk Plugin
  • Email Marketing Plugin

Upgrading

  • Upgrading Codapult

Developer Tools

  • AI Agents & IDEs
  • MCP Server
  • Testing
  • Build Your First Feature with Codapult MCP
  • How Guard Blocks an Architectural Regression
Security

Data Retention Policy

Recommended retention baseline for application data, logs, webhooks, backups, and user deletion.

Codapult should keep operational data only for the period needed to run the product, investigate failures, and satisfy the deployment's contractual requirements. The table below is a recommended deployment baseline, not an automatic application purge. The operator must configure and verify the actual retention windows for each environment.

Recommended deployment baseline

DataDefaultLifecycle
Sessions and verification tokensUntil expiryCleanup jobs remove expired records.
AI usage and audit recordsWhile the organization account is active, unless a shorter period is configuredOrganization deletion/export controls the account lifecycle.
Webhook delivery payloads30 daysConfigure a cleanup job or database policy; keep status and identifiers longer only when operationally required. Payloads can contain sensitive provider data.
Application logs30 daysConfigure the hosting log drain or platform retention to match this target.
Traces and error events30 daysConfigure OpenTelemetry and Sentry retention separately.
Database backups30 daysConfigure provider retention; it can be longer for legal or disaster-recovery requirements.
Object-storage uploadsUntil deleted by the owning feature or account workflowEnable bucket versioning and lifecycle expiration when the product does not require historical versions.

Deletion and export

Account deletion and GDPR workflows remove or anonymize application records covered by the feature. A restore point, provider log, trace, or object-storage version is a separate copy and follows its provider retention policy; it is not immediately removed by an application transaction. Do not promise erasure from backups until the provider's expiry or purge procedure has completed.

Before launch, record the configured retention and owner for:

  1. the primary database and point-in-time recovery;
  2. object storage and versioned objects;
  3. application logs, traces, and error tracking;
  4. webhook payloads and admin audit records;
  5. exports and disaster-recovery copies.

Review the policy when adding a table containing personal or payment data. Keep payload access restricted to the operational roles that need it, and use the existing redaction paths for logs, traces, and error reporting.

SCIM ProvisioningSecurity