Security and data handling

You are about to send us somebody else's confidential agreement

Your pole attachment agreement is not yours alone. It carries the owner's rates, terms and methodology, and it almost certainly carries a confidentiality clause. Your invoices carry your build. Handing both to an outside auditor is the part of this that keeps a network engineer awake, and the first question is usually the same one.

No, your documents are not training anybody's model

PoleProof's application does not depend on a model provider. Not one is in the dependency list, and there is no code path in the product that sends a document to one. This is not a policy we are asking you to trust. It is a property of what we built, and it is the kind of claim you can hold us to.

Our audits are performed by a human against a written rule library. Every finding traces to a document, a clause, a tariff section or a federal formula, with the arithmetic shown.

Where your documents go, and what reaches them

Your documents go to one place: a private storage bucket in a US East region, restricted by file type and size, readable only by the account that owns them. They are never made public and never given a shareable link.

Behind it, the database is locked by default rather than by exception:

Row level security is on for every table.

What we delete, and when it actually happens

We publish periods and we run the deletion. A job runs every day, removes the files themselves before removing the records that point at them, and refuses to touch anything that is not genuinely past its own expiry date.

Your documentsWe keep them for
If you never become a client90 days
If you do12 months after your engagement closes
Findings and the audit trail behind them7 years

Those are ceilings, not targets. Ask us to delete sooner and we will, and a verified deletion request completes within 30 days.

Why seven years on findings: if you are building with federal money, your findings are part of your support for that award record, and you will need them long after the invoice is settled.

The site

Every page is served with a content security policy that allows no third party script, no framing by another site and no plugin content, along with the standard set of browser protections. Production builds ship no source maps.

What we do not claim

We are a new company and we would rather you heard this from us than found it out.

We do not hold a SOC 2 report. We are not asking you to treat us as though we do. What we can give you instead is specificity: exactly what is built, exactly what reaches your documents, and exactly when they are deleted, all of which is written above and none of which is a slogan.

If your procurement process needs something we have not listed, ask. We will tell you plainly whether we have it.

Have a question before you send anything

Send it to hello@getpoleproof.com and a person will answer it. You do not need to upload a document to ask.