← Back to Pondral
Security
How we keep your data safe.
We build security into the product, audit it internally, and document it for your procurement review.
Posture
- GDPR / CCPA: designed for compliance; our Data Processing Addendum is published at /dpa and is incorporated into our Terms of Service, so it takes effect when you accept them — a countersigned copy is available on request
- Encryption: at rest and in transit
- Access: least-privilege, audit-logged
Encryption
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256, managed by our infrastructure providers (Supabase and Vercel). Customer data is logically isolated per workspace with row-level security.
Access controls
- SSO via SAML 2.0 and Google Workspace (Agency plans); other SAML identity providers such as Okta and Azure AD connect via the standard SAML flow
- Role-based access control with audit logs
- Least-privilege production access, audit-logged
Incident response
If we confirm a security incident affecting your data, we notify affected customers without undue delay and within 72 hours of confirmation. We run an internal post-incident review and share a summary with affected customers on request.
For full vendor-review packages, see /compliance. Vulnerability disclosure: security@pondral.com.
Last updated July 2026Run a free audit →