When a subject erasure request is processed, the customer's compliance officer can extract,
for that request:
- The signed disposal receipt, with the operator-root public key needed to verify it.
- The Merkle inclusion proof showing the receipt is sealed in the audit chain at a specific
position, with the chain hash before and after.
- A timestamped record of which tenant CMK was destroyed, which ciphertext objects were
dependent on it, and which retention policy applied to each.
- A reference to the KMS audit log entry recording the destruction, signed by the KMS itself.
Customers running a SOC 2 or HIPAA audit feed this packet directly to their auditor.
For GDPR Art. 17 Supervisory-Authority response, the packet provides the verifiable
statement of completion that data-protection regulators look for.