Configure retention, exports and access logging to match what an auditor will actually ask for.
Under Settings > Data > Retention, set detection, alert and access-log retention to at least what your framework or auditor requires; the default is tuned for operational use, not long-term audit evidence.
Enable detailed access logging under Settings > Security > Audit log, capturing every login, config change and export, not just detection events.
Configure a scheduled export of detection and audit logs to your archive or SIEM, so evidence exists independently of Linivo's own retention window.