Voog Technology
File Retention Policy
Last updated: August 1, 2026
Scope
This policy covers invoices and technical documents uploaded for hosting assessments and audits. It does not authorize uploading credentials, secrets, private keys, or full production database exports.
Default retention
Eligibility-only uploads should be deleted when no longer needed and ordinarily within 90 days of closure. Paid-audit files should be deleted within 180 days after audit delivery or project closure unless the customer requests earlier deletion or a legitimate accounting, dispute, security, or legal need requires limited retention.
Private storage
Uploads use randomized storage keys outside the public web root. Downloads require an authenticated administrator. Executable types are rejected; size, extension, MIME type, and file signatures are checked. Malware scanning is used when configured.
Deletion
Authorized administrators can mark an upload deleted and remove the corresponding private object. Customers may request deletion at privacy [at] voog.tech. Backup copies may expire on the normal backup lifecycle rather than immediately.