ConformOps
How it worksWhat you getPricingCompareReporting deadlinesSecurityCRA resources
Sign inStart free
How it worksWhat you getPricingCompareReporting deadlinesSecurityCRA resourcesSign in
Trust

Account and product deletion

Last updated 29 August 2026

Archive and deletion are different

Archiving is the normal reversible lifecycle action. It stops new processing, releases applicable product allocation or recurring assignment, and keeps the historical evidence chain readable. Permanent deletion is a separate danger-zone action that removes the product evidence chain and cannot be undone.

Permanent product deletion

Only the workspace Owner can permanently delete a product. The Owner must open a separate confirmation dialog, type the uppercase product-specific phrase exactly, and acknowledge the retention policy before the server accepts the request. A Member or Admin cannot call the deletion boundary directly.

The procedure removes product rows and linked assessments, source snapshots, findings, evidence, approvals, artifacts, supplied SBOMs, vulnerability records, reporting records, reviewer links and views, GitHub repository selections, R2 objects, and Vectorize evidence vectors. Each planned operation has a recorded state. The request is complete only when every store verifies; a failed store leaves it partial and the hourly job retries it.

Product deletion does not cancel an Organization subscription or remove statutory transaction history. A recurring coverage slot assigned to the product becomes unassigned, while its subscription and billing continue until the Owner changes or cancels them through billing controls. Download any evidence you need before deletion.

Account deletion

An account holder can request account erasure from workspace settings by typing the account email and acknowledging retention. An Owner cannot start deletion while any workspace they still own has an active or trialing subscription. They must transfer ownership to another member or cancel the subscription and wait until it is no longer live. Deletion never cancels a subscription automatically. An unsubscribed workspace still owned by the account holder is permanently deleted with all its products and evidence. Admins and Members are removed from workspaces owned by someone else, while those workspaces survive. The procedure removes credentials, sessions, GitHub token ciphertext, and memberships. Surviving attribution is replaced by a stable pseudonym rather than reassigned to someone else. Account and owned-workspace deletion are irreversible.

What remains and why

  • Statutory billing and transaction records needed for accounting, tax, fraud prevention, or disputes.
  • Webhook delivery keys needed to prevent a replayed event from being processed twice.
  • The erasure request, step journal, verification report, and minimal audit proof.
  • Shared service-operated legal and vulnerability reference catalogs that are not customer data.

Retained records are limited to the stated purpose and are not a copy of the product evidence chain. See the Privacy notice and Data processing agreement for the legal context.

ConformOps
How it worksPricingReporting deadlinesSecurityCRA resourcesAI infoTrust centerDPALegal noticePrivacyTerms
Readiness assistance, not legal certification.