SecretWolf

Compliance

Straight answers about how SecretWolf handles data, and what our design gives you for your own compliance. This complements the security page — we don't repeat the encryption detail here.

What our design does for your compliance

Because secrets are encrypted and hard-deleted on view or expiry, and the audit log keeps metadata only, using SecretWolf tends to reduce the sensitive data you hold:

This is context to help your own assessment — it isn't legal advice, and it doesn't make you compliant on its own.

UK data residency

SecretWolf runs on UK infrastructure, with traffic over HTTPS end to end. Secret payloads and attachments are encrypted at rest and hard-deleted on view or expiry.

Retention and deletion

Sub-processors

We use a small number of processors to run the service:

We'll keep this list current and note material changes here.

Data processing agreement

We can provide a data processing agreement (DPA) for business customers who need one for their own records. Ask us and we'll send it over.

Questions

For a security review, a DPA, or anything not covered here, contact us — say what you need and it reaches the right person. Reporting a vulnerability? See responsible disclosure.

Built to hold less of your data

One-time, encrypted, audited. See exactly how on the security page.

How it's secured