Security

A privacy company that practices privacy

We exist to remove your data from brokers. We take the security of that data seriously. Here is how we protect it, and the commitments we make to you.

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Your personal information never exists in plaintext outside of active processing.

Minimal Data Collection

We collect the minimum information needed to match and remove broker listings: your name, email, and any additional identity details (such as address history or phone numbers) required by specific brokers. We do not store SSNs, financial data, or government IDs.

Infrastructure Security

Hosted on SOC 2-certified cloud infrastructure with isolated tenant environments. Automated security patching and continuous monitoring.

Audit Logging

Every removal action is logged with timestamps and verification. You can see exactly what was removed, when, and from where.

Access Controls

Role-based access control with mandatory MFA for all employees. No single person can access user data without audit trail.

No Data Monetization

We will never sell, share, or monetize your data. Our revenue comes from subscriptions, not from harvesting the information we are supposed to protect.

Our commitments to you

We will never sell your data to third parties
We delete your data within 30 days of account cancellation
We notify you within 72 hours of any security incident
We publish a transparency report annually
We undergo annual third-party security audits
We comply with CCPA, CPRA, and all applicable state privacy laws

Penumbras is a California-based company.
Questions about our security practices? Contact [email protected]