Your pole attachment agreement is not yours alone. It carries the owner's rates, terms and methodology, and it almost certainly carries a confidentiality clause. Your invoices carry your build. Handing both to an outside auditor is the part of this that keeps a network engineer awake, and the first question is usually the same one.
PoleProof's application does not depend on a model provider. Not one is in the dependency list, and there is no code path in the product that sends a document to one. This is not a policy we are asking you to trust. It is a property of what we built, and it is the kind of claim you can hold us to.
Our audits are performed by a human against a written rule library. Every finding traces to a document, a clause, a tariff section or a federal formula, with the arithmetic shown.
Your documents go to one place: a private storage bucket in a US East region, restricted by file type and size, readable only by the account that owns them. They are never made public and never given a shareable link.
Behind it, the database is locked by default rather than by exception:
Row level security is on for every table.
We publish periods and we run the deletion. A job runs every day, removes the files themselves before removing the records that point at them, and refuses to touch anything that is not genuinely past its own expiry date.
| Your documents | We keep them for |
|---|---|
| If you never become a client | 90 days |
| If you do | 12 months after your engagement closes |
| Findings and the audit trail behind them | 7 years |
Those are ceilings, not targets. Ask us to delete sooner and we will, and a verified deletion request completes within 30 days.
Why seven years on findings: if you are building with federal money, your findings are part of your support for that award record, and you will need them long after the invoice is settled.
Every page is served with a content security policy that allows no third party script, no framing by another site and no plugin content, along with the standard set of browser protections. Production builds ship no source maps.
We are a new company and we would rather you heard this from us than found it out.
We do not hold a SOC 2 report. We are not asking you to treat us as though we do. What we can give you instead is specificity: exactly what is built, exactly what reaches your documents, and exactly when they are deleted, all of which is written above and none of which is a slogan.
If your procurement process needs something we have not listed, ask. We will tell you plainly whether we have it.
Send it to hello@getpoleproof.com and a person will answer it. You do not need to upload a document to ask.