Compliance
Straight answers about how SecretWolf handles data, and what our design gives you for your own compliance. This complements the security page — we don't repeat the encryption detail here.
What our design does for your compliance
Because secrets are encrypted and hard-deleted on view or expiry, and the audit log keeps metadata only, using SecretWolf tends to reduce the sensitive data you hold:
- Data minimisation by default. A one-time secret is destroyed once it's read — there's no long-lived copy of a credential to appear in a subject access request or a breach.
- An accountability record without the data. The audit log evidences who received what and when (metadata only, never the secret), which is exactly the kind of record the UK GDPR accountability principle asks for — without retaining the sensitive value itself.
- Purpose-built deletion. Hard delete on view or expiry means "right to erasure" for the secret content is the default behaviour, not a manual process.
- Recipient control. Optional email verification means a credential only reveals to the person you sent it to.
This is context to help your own assessment — it isn't legal advice, and it doesn't make you compliant on its own.
UK data residency
SecretWolf runs on UK infrastructure, with traffic over HTTPS end to end. Secret payloads and attachments are encrypted at rest and hard-deleted on view or expiry.
Retention and deletion
- Secret content and attachments: hard-deleted on first view (or when a multi-view limit is reached) or at expiry — whichever comes first.
- Audit records: metadata only. On the Business plan you set your own retention period; older records are removed automatically.
- Account data: retained while your workspace is active; removed on account closure.
Sub-processors
We use a small number of processors to run the service:
- Stripe — subscription billing and payment processing.
- Twilio SendGrid — transactional and notification email.
- UK hosting — the application and database run on P2xel-operated UK infrastructure.
We'll keep this list current and note material changes here.
Data processing agreement
We can provide a data processing agreement (DPA) for business customers who need one for their own records. Ask us and we'll send it over.
Questions
For a security review, a DPA, or anything not covered here, contact us — say what you need and it reaches the right person. Reporting a vulnerability? See responsible disclosure.