{
  "slug": "data-retention-storage-cost",
  "title": "Security Data Retention Storage Cost Calculator",
  "heading": "Log & Data Retention Storage Cost Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/data-retention-storage-cost",
  "summary": "Project multi-year storage cost for security logs under compliance retention rules.",
  "description": "Compliance frameworks (PCI DSS wants 1 year with 3 months immediately available, HIPAA commonly drives 6 years, SOC 2 typically 1 year of audit-relevant logs, some state breach laws and cyber insurance requirements push further) force organizations to retain security log data far longer than operational needs alone would justify, and storage cost compounds because you're storing every prior period simultaneously during the retention window, not just the current period. This calculator projects total storage volume across daily ingestion rate and retention period, splits it between hot storage (fast, expensive, needed for active search) and cold/archive storage (cheap, slower to retrieve, fine for compliance-only data past a certain age), and produces an annual cost. Most SIEM cost overruns trace back to nobody modeling this compounding effect before committing to a retention policy, discovering only at renewal that 400GB/day for 400 days of hot retention is a very different number than 400GB/day for 30 days.",
  "formula": "Total stored volume = daily ingestion (GB) × retention days. Hot cost = hot-tier volume × hot rate/GB/month × 12. Cold cost = cold-tier volume × cold rate/GB/month × 12.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=data-retention-storage-cost",
  "inputs": [
    {
      "id": "dailyIngestionGb",
      "label": "Daily log ingestion (GB)",
      "kind": "number",
      "hint": null,
      "default": 150,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "hotRetentionDays",
      "label": "Hot/searchable retention (days)",
      "kind": "number",
      "hint": null,
      "default": 90,
      "unit": null,
      "min": 1,
      "max": 3650
    },
    {
      "id": "coldRetentionDays",
      "label": "Cold/archive retention beyond hot (days)",
      "kind": "number",
      "hint": null,
      "default": 640,
      "unit": null,
      "min": 0,
      "max": 3650
    },
    {
      "id": "hotRatePerGb",
      "label": "Hot storage cost ($/GB/month)",
      "kind": "number",
      "hint": null,
      "default": 0.35,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "coldRatePerGb",
      "label": "Cold/archive storage cost ($/GB/month)",
      "kind": "number",
      "hint": null,
      "default": 0.02,
      "unit": null,
      "min": 0,
      "max": null
    }
  ],
  "outputs": [
    {
      "id": "totalAnnualCost",
      "label": "Total annual storage cost",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "hotAnnualCost",
      "label": "Hot/searchable tier cost",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "coldAnnualCost",
      "label": "Cold/archive tier cost",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "totalVolumeGb",
      "label": "Total volume under retention (GB)",
      "format": "number",
      "hint": null,
      "primary": false
    },
    {
      "id": "hotVolumeGb",
      "label": "Hot tier volume (GB)",
      "format": "number",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Daily log ingestion (GB): 150",
      "Hot/searchable retention (days): 90",
      "Cold/archive retention beyond hot (days): 640",
      "Hot storage cost ($/GB/month): 0.35",
      "Cold/archive storage cost ($/GB/month): 0.02"
    ],
    "outputs": [
      "Total annual storage cost: $79,740",
      "Hot/searchable tier cost: $56,700",
      "Cold/archive tier cost: $23,040",
      "Total volume under retention (GB): 109,500",
      "Hot tier volume (GB): 13,500"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter daily log ingestion (gb).",
      "Enter hot/searchable retention (days).",
      "Enter cold/archive retention beyond hot (days).",
      "Enter hot storage cost ($/gb/month).",
      "Enter cold/archive storage cost ($/gb/month).",
      "Read your total annual storage cost on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "dailyIngestionGb": 90,
        "hotRetentionDays": 54,
        "coldRetentionDays": 384,
        "hotRatePerGb": 0.21,
        "coldRatePerGb": 0.012
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "dailyIngestionGb": 150,
        "hotRetentionDays": 90,
        "coldRetentionDays": 640,
        "hotRatePerGb": 0.35,
        "coldRatePerGb": 0.02
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "dailyIngestionGb": 240,
        "hotRetentionDays": 144,
        "coldRetentionDays": 1024,
        "hotRatePerGb": 0.5599999999999999,
        "coldRatePerGb": 0.032
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Why does hot storage cost so much more than cold?",
      "a": "Hot/searchable tiers keep data indexed and immediately queryable for real-time detection and investigation, which requires more compute and faster disk (SSD/NVMe-backed) behind the scenes; cold/archive tiers just need durable, cheap storage since you rarely query it except for compliance audits or historical forensic investigation, and can tolerate minutes-to-hours retrieval time."
    },
    {
      "q": "How long should hot retention actually be?",
      "a": "90 days is a common baseline that covers most detection use cases including slow-moving attacks, while satisfying PCI DSS's requirement for 3 months of immediately available log data; extend it if your SOC regularly needs to correlate incidents that unfold over longer windows, but every extra day compounds cost since you're now storing that day's volume at hot rates for the entire window."
    },
    {
      "q": "Can I just delete logs after the hot retention period instead of archiving?",
      "a": "Only if no compliance framework or contractual obligation requires longer retention; PCI DSS, HIPAA, and many cyber insurance policies or customer security addendums specify minimum total retention (often 1-6+ years) regardless of whether the data needs to be searchable, which is exactly the gap cold/archive tiers are built to fill cheaply."
    },
    {
      "q": "What's the fastest way to cut this cost without reducing retention?",
      "a": "Filter and reduce ingestion volume at the source before it hits your SIEM or log platform: dropping verbose debug-level logs, deduplicating repetitive events, and sending only security-relevant fields instead of full raw payloads routinely cuts ingestion volume 30-50% without losing detection value."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/siem-log-ingestion-cost",
    "https://www.revenuelab.fyi/toolbox/soc2-audit-cost",
    "https://www.revenuelab.fyi/toolbox/edr-licensing-cost-per-endpoint"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Security Data Retention Storage Cost Calculator (https://www.revenuelab.fyi/toolbox/data-retention-storage-cost)"
}