Data Retention & Deletion Policy
Effective date: 03 February 2026
Last updated: 03 February 2026
1. Principles
We aim to retain data only as long as necessary for delivering the Services, security, support, and legal/accounting requirements.
2. Retention periods by plan
Scan Results & Reports
Audit and security logs may be retained longer for investigation and compliance purposes.
3. Retention by category
Your plan may offer configurable retention with maximum limits. Typical retention periods (subject to plan/contract):
Retention Periods
Account and billing records
User info, invoices, payment history
Scan metadata and findings
Vulnerability data, scan configurations
Reports (PDF/HTML)
Generated reports, share links
Audit logs
Security events, access logs
Support tickets
Communications, attachments
4. Customer-configurable retention
Organization administrators may select retention periods up to the plan's maximum. Some data types (e.g., billing records) may not be deletable immediately due to legal obligations.
5. Deletion on termination
Upon account closure or termination:
- we delete or de-identify Customer Data within a reasonable period, except where retention is required for legal obligations, security investigations, or disputes.
- backups follow a normal expiry cycle; deleted data may persist in backups until backups expire.
6. Exports
Where supported by plan, customers may export reports and selected data prior to deletion.
Related policies: