Mend.io Data Retention & Archiving Policy

We believe in transparency and control when it comes to your data. This page outlines how long we retain customer data, audit logs, backups, and account information—so your organization can plan for compliance, security, and business continuity.

Audit logs: Retention period is 90 days.

Backups: Retention period is 30 days.

Account data: Retained as long as your Mend.io account is active

Upon Termination/Expiration: The Customer Account and all information contained therein will be deleted following termination/ expiration of the Customer’s subscription to the relevant Mend Service. When we delete Mend Account information, it will be deleted from the active database but may remain in our archives (see backup retention above).

Exceptions: Notwithstanding the foregoing, we may retain your data for longer periods of time for as long as we consider necessary for the following purposes: to comply with our legal and contractual obligations, to protect ourselves against, and to resolve potential disputes, and to enforce our agreements

Please note that except as required by applicable law and as specifically indicated under this Data Retention Policy, we will not be obligated to retain Customer Data for any particular period, or to provide you with notice in connection with data deletion post-termination/expiration of your subscription.

Understanding Data Retention in Application Security

Data retention and archiving policies play a critical role in helping organizations maintain security, meet compliance requirements, and manage system performance. At Mend.io, we follow industry best practices to minimize data exposure, protect customer information, and ensure we only retain data for as long as it’s needed.

Our policies are designed with the needs of enterprise customers in mind, especially those in regulated industries where retention rules may vary. We balance operational efficiency, legal compliance, and customer expectations by implementing clear data lifecycle management practices.

Why Retention Periods Matter

Retention timelines for backups, audit logs, and account data help:

  • Reduce storage costs and complexity
  • Minimize risk of unauthorized access to old data
  • Support compliance with data privacy regulations like GDPR and CCPA
  • Improve system performance and scalability

By clearly defining retention periods, Mend.io gives customers the confidence and predictability they need to manage their own security and compliance strategies.