Security & trust

Delist handles sensitive identity and exposure data. This page states the controls we can substantiate, the data that leaves our systems to perform the service, and the assurance work we have not yet completed.

AES-256-GCM profile encryption TLS 1.2/1.3 No data sales No SOC 2 claim

Security facts last reviewed August 27, 2026.

Architecture

How your data is protected

AES-256-GCM profile encryption

The canonical customer profile record is encrypted with AES-256-GCM using a scrypt-derived key before it is written to the database. Authentication tags detect modification as well as protect confidentiality.

Honest encryption boundary

Not every operational record is application-layer encrypted. Scan findings, workflow and email records, listing URLs, and removal evidence may contain personal information and are protected by infrastructure and application access controls. We do not describe the entire datastore as AES-encrypted.

TLS in transit

The public web edge accepts TLS 1.2 and TLS 1.3. Data sent onward to service providers and removal targets uses their secured network endpoints where available; “end-to-end encrypted” would be inaccurate for an opt-out service.

Temporary scan workspace

A scan job receives its own server-side directory. Decrypted profile files are permission-restricted, and cleanup runs after job expiry and during startup recovery. This is bounded temporary disk processing, not memory-only processing.

Commitments

Our commitments to you

Automated, with operational access

Scanning and much of the removal workflow are automated. Authorized operators may access customer information when needed to run, support, secure, or troubleshoot the service. We do not promise that no person can ever view a customer record.

We don't sell your data. Ever.

Subscriptions are our only revenue. There's no second business model here.

Purpose-limited collection

We collect identity details, scan inputs and results, removal workflow records, security and operational logs, and first-party product events needed to provide and improve the service. We do not use third-party advertising trackers or sell this information.

Service providers disclosed

Delist relies on providers for hosting and storage, payments, email, search, breach lookup, page retrieval, and automated analysis. Each receives only the information needed for that function. See the Privacy Policy for the current list and purposes.

Account deletion with stated exceptions

Account deletion removes the profile and linked application records and attempts to cancel active billing. Private evidence files age out under a storage lifecycle of up to 365 days. Limited payment, audit, security, and anti-reingestion records may remain when required.

Assurance

Current assurance status

SOC 2No report currently published or claimed
Independent penetration testNo report currently published
Internal security reviewSecurity findings and remediations are tracked in the engineering repository
Automated controlsSecurity-focused tests cover authentication, authorization, input handling, erasure paths, webhooks, and other high-risk boundaries

Internal review and automated tests are useful controls, but they are not equivalent to independent certification. We will update this page when the assurance status changes.

Lifecycle

What happens to your data

1

You provide your info

Your full name, email address, US phone number, and home address, with birth year optional. The canonical profile record is encrypted before database storage.

2

We scan for you

The service decrypts the profile for scanning. A permission-restricted temporary job file may be used, and findings are stored for the report and future comparison.

3

We submit removals

We send the identifying details needed to locate and suppress your record to data brokers, people-search sites, and supporting service providers. Workflow and delivery records are retained to track the request.

4

Monthly full scans

Paid plans run a full scan each month. Findings and removal history are retained while the service needs them to compare results, show progress, and re-file eligible requests.

FAQ

Security FAQ

Questions about how we handle your data.

Who can access my personal information?

Delist uses automated systems for scanning and removal work, but authorized operators may access customer information when needed to run, support, secure, or troubleshoot the service. Service providers receive the data needed for their role, and removal targets receive the information needed to identify and suppress a record.

What is encrypted at rest?

The canonical customer profile record is encrypted with AES-256-GCM using a scrypt-derived key before it is stored. Scan findings, workflow records, email records, and evidence may be stored separately and are protected by infrastructure and application access controls; Delist does not claim that every database field is application-layer encrypted.

What analytics does Delist collect?

Delist uses first-party, cookie-free event collection. It records a session-scoped random identifier, page path, attribution parameters when present, and allowlisted product events. Once you run a scan or sign in, those session events are associated with your account. The public event endpoint is designed not to collect scan answers or profile fields.

What happens when I delete my account?

Account deletion removes the profile and linked application records and cancels an active subscription when possible. Evidence files can remain in private storage until their lifecycle deletion, currently up to 365 days. Limited payment, audit, security, and anti-reingestion records may remain where legally or operationally necessary.

What happens if there is a security incident?

Encryption reduces the impact of some compromise scenarios but does not make a breach harmless. Delist investigates incidents and will provide legally required notices. The effect depends on which systems and records are involved.

Does Delist use third-party service providers?

Yes. Delist uses providers for hosting and storage, payments, email, search, breach lookup, page retrieval, and automated analysis. It also sends identifying information to removal targets when needed to process an opt-out. Delist does not sell personal information or share it for third-party advertising.

Is Delist SOC 2 certified?

No SOC 2 report or independent penetration-test report is currently published for Delist. The service has internal security reviews and automated security tests, but those are not substitutes for independent assurance.

Your privacy starts with a scan.

See where you are exposed, review the result, and decide whether ongoing removal is right for you.