Trust & security
We hold sensitive data. Protecting it is the whole job.
To remove your information from the web, we have to hold a concentrated record of it. We treat that responsibility as the core of the company — here's exactly how.
🔒
Encrypted, always
Your profile is encrypted in transit (TLS) and at rest. Sensitive fields are sealed with authenticated encryption keys held separately from the database.
🧹
Minimal by design
We collect only what's needed to find and remove your records, store it for as long as you're a member, and delete it within 30 days of cancellation.
👁
Redacted logging
Our systems log activity using redacted identifiers, never raw personal data. Engineers debug the pipeline without ever seeing your information.
Our security practices
- Authenticated encryption at rest for customer profiles and breach data, with keys managed outside the application database.
- Access tokens & least privilege — every customer endpoint requires the customer's own token; internal access is restricted and reviewed.
- Rate limiting & abuse controls on scanning and identity-verification endpoints to prevent enumeration or scraping.
- Identity-verification gate before any sensitive value (such as an SSN's last four) is ever shown — and we never display it in email.
- Encrypted backups with tested restores, and a written incident-response plan rehearsed before launch.
- Vendor diligence — sub-processors operate under confidentiality and data-processing terms; we never sell or share your data.
Our promises
- We are an authorized agent, not a data broker. We act on your behalf to remove data — we never buy, sell, or trade it.
- Official channels only. Our automation uses each broker's published opt-out process. We do not bypass access controls or scrape behind logins.
- Your data, your call. Export everything we hold or delete it permanently, anytime, from your account — no friction, no retention games.
- No dark patterns. Cancelling is one click. We'll show you the trade-off honestly, then respect your decision.
Compliance & roadmap
UK GDPR authorized agentOperating today under California's consumer-privacy framework.
Live
California DROP integrationFiling deletions through the state Delete Request & Opt-out Platform.
Live
SOC 2 Type IIIndependent attestation of our security controls.
In progress
Independent effectiveness testingSubmitting our removal results to third-party evaluation.
Planned
Status reflects current build intent for this preview; certifications are pursued once revenue supports them.
Sub-processors
We use a small set of vetted providers, each under a data-processing agreement:
Cloud hostingApplication & encrypted database
PaymentsStripe — billing only (no card storage by us)
Email deliveryTransactional notifications
Residential proxiesTo reach broker opt-out pages
CAPTCHA solvingUsed only on official opt-out forms
Breach intelligenceDark-web exposure monitoring
Responsible disclosure
Found a vulnerability? We want to hear from you. Email security@idsealed.com with details and steps to reproduce. We'll acknowledge promptly, keep you updated, and credit researchers who report in good faith. Please don't access other people's data or degrade the service while testing.
Your data is yours
Export everything we hold, or delete it permanently — anytime, from your account.
Manage my data