> ## Documentation Index
> Fetch the complete documentation index at: https://docs.varios-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Decommissioning

> How to shut down a self-hosted installation and securely remove all data

When decommissioning, you remove all data of the installation and revoke all access VARIOS AI had to other systems. For an instance hosted by us, contact support.

<Warning>
  These steps cannot be undone. Check beforehand whether you still need data or logs due to retention obligations.
</Warning>

## Remove data

<Steps>
  <Step title="Back up data you must retain">
    Export what you must keep, such as the audit, sign-in and DLP logs from `Data/Logs`.
  </Step>

  <Step title="Stop services and remove containers">
    Change to the installation directory and run:

    ```bash theme={null}
    docker compose down --volumes --rmi all
    ```
  </Step>

  <Step title="Delete the installation directory">
    Delete the entire installation directory. It contains all data of the installation:

    | Directory or file | Content |
    | - | - |
    | `.env`, `docker-compose.yml` | Configuration and credentials |
    | `Postgres` | Database with chats, settings and search indexes |
    | `Redis` | Cache and sessions |
    | `Data/Data/Persistent` | Uploaded files and the installation key |
    | `PostgresBackups` | Database backups |
    | `Data/Logs` | Logs |
    | `Web/_Resources` | Published files |
    | `traefik` | TLS certificates |
  </Step>

  <Step title="Delete disks and backups">
    Delete the virtual machine including its disks and snapshots. Remove copies of the installation directory from your backup systems. Follow your organization's deletion requirements.
  </Step>
</Steps>

<Note>
  Stored content is encrypted with the key in `Data/Data/Persistent`. However, not all data is stored encrypted, for example search indexes. Therefore always delete the entire directory, not just the key.
</Note>

## Revoke access

| Access | Where to revoke |
| - | - |
| AI provider API keys from **Admin** > **Credentials** | In the respective provider's portal |
| OAuth clients for connectors and MCP servers | At the respective service |
| Credentials for proxy servers and database connectors | In the respective systems |
| DNS record and firewall rules | In your network infrastructure |
| Office add-ins | In the Microsoft 365 admin center |

Also revoke the connection to your identity provider:

<Tabs>
  <Tab title="Microsoft Entra ID">
    | Access | Where to revoke |
    | - | - |
    | App registration with client secret | **Microsoft Entra ID** > **App registrations** |
    | Enterprise application with user assignments and provisioning (SCIM) | **Microsoft Entra ID** > **Enterprise applications** |
  </Tab>

  <Tab title="Keycloak">
    | Access | Where to revoke |
    | - | - |
    | Client with client secret and service account | Keycloak admin console |
    | Realm, if it was created only for VARIOS AI | Keycloak admin console |
    | Bind account for LDAP synchronization | Your directory service |

    <Note>
      If you run Keycloak exclusively for VARIOS AI, also decommission Keycloak with its database and delete its data and backups using the same steps.
    </Note>
  </Tab>
</Tabs>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.