Both capture paths produce the same decision-grade record of each turn — the watcher
(reading the transcript) for Claude Code + Claude Desktop, and the gateway for agent SDKs.
This page is the authoritative list of what that includes — and what it excludes.
Captured per turn
Not captured
The PII nuance
Prompt/response content and tool calls are captured as-is — on the gateway path from the
request/response, and on the watcher path from the local session transcript (which already
contains that content on the machine, before Enfors is involved). Raw content lives in
ingest logs with 14-day retention, encrypted at rest.When a turn is reconstructed into the durable decision ledger, PII is scrubbed, and it
is removed from API responses. So raw content is transient; the long-lived, queryable record
is scrubbed.
See Tenancy, Privacy & PII for the product-side view and
Data residency & retention for retention periods.