Pondral
← Back to Pondral
Security

How we keep your data safe.

We build security into the product, audit it internally, and document it for your procurement review.

Posture

  • GDPR / CCPA: designed for compliance; our Data Processing Addendum is published at /dpa and is incorporated into our Terms of Service, so it takes effect when you accept them — a countersigned copy is available on request
  • Encryption: at rest and in transit
  • Access: least-privilege, audit-logged

Encryption

All data is encrypted in transit with TLS 1.2+ and at rest with AES-256, managed by our infrastructure providers (Supabase and Vercel). Customer data is logically isolated per workspace with row-level security.

Access controls

  • SSO via SAML 2.0 and Google Workspace (Agency plans); other SAML identity providers such as Okta and Azure AD connect via the standard SAML flow
  • Role-based access control with audit logs
  • Least-privilege production access, audit-logged

Incident response

If we confirm a security incident affecting your data, we notify affected customers without undue delay and within 72 hours of confirmation. We run an internal post-incident review and share a summary with affected customers on request.

For full vendor-review packages, see /compliance. Vulnerability disclosure: security@pondral.com.

Last updated July 2026Run a free audit