Pilum.ioTRACK A
AuditsMethodPricingAssuranceCoverageFAQ
Get Audited

Data Retention Policy

Last updated: March 2026

Retention Schedule

Data TypeRetention PeriodDeletion Method
Tier 1 scan data & findings90 days from deliverySecure deletion on schedule
Tier 2 scan data & findings365 days from deliverySecure deletion on schedule
Guardian subscription dataSubscription + 90 daysSecure deletion post-subscription
Authorization documents3 years from signingArchived, then deleted
Payment records (Polar.sh)Per Polar.sh policyNot held by Pilum.io
Source code (Tier 2 repo)Session only — deleted after PDF generatedSecure deletion immediately post-scan
Anonymized aggregate findings dataIndefiniteNever contains identifying information
Client email addressesDuration of relationship + 90 daysDeleted on request

Early Deletion

Email security@pilum.io with subject “Data Deletion Request — [your domain]”. Processed within 72 hours. We will confirm deletion in writing.

What “Deletion” Means

Files are securely deleted from the operator’s machine. Database rows are anonymized (client identifiers replaced with null) before aggregate data is retained. Backups are purged on their next rotation cycle (weekly).

What We Retain Indefinitely (Anonymized, Non-Identifiable)

Vulnerability type frequencies, severity distributions, false positive rates, tool fingerprint accuracy scores. This data has no client identifiers attached and cannot be used to reconstruct any client’s findings.

Pilum.io
Responsible DisclosurePrivacy PolicyTerms of ServiceData RetentionContact

© 2026 Pilum.io — Adversarially verified. Professionally delivered.