Security
An overview of the measures protecting customer data, and how to report a vulnerability.
Effective August 22, 2026
This page summarizes the security measures applied to the PonderOS service by PonderOS Labs LLC. It is provided for information only, does not form part of any contract, and does not create any warranty or representation.
1. Data Protection
Customer data is encrypted in transit using industry-standard transport-layer security, and is encrypted at rest by our infrastructure providers. Access to production systems is limited to personnel who require it in order to operate and support the Service, and is used only for that purpose.
2. Access Control and Isolation
Each customer’s data is logically isolated from that of every other customer, and access is enforced at the data layer on the basis of authenticated identity. Within a customer’s account, permissions are governed by workspace roles that determine which users may view and modify content.
3. Authentication
Authentication is performed through Google sign-in or a one-time code delivered to the registered email address. We do not store passwords. Sessions are maintained using secure, HTTP-only cookies, and all application interfaces require authentication. Programmatic access credentials are stored only in hashed form, are displayed once on creation, and may be revoked by the customer at any time. Authentication and application interfaces are subject to rate limiting.
4. Availability and Backup
Our infrastructure providers perform automated, encrypted backups of production data on a regular schedule for disaster-recovery purposes. Backups are not a substitute for customer-controlled copies; the Service provides a self-service export function permitting customers to retain their own copies of their data in standard formats, and documents retain a revision history within the Service.
5. Service Providers
We engage the service providers listed below, in each case under written terms requiring appropriate technical and organizational security measures. The same list appears in our Privacy Policy.
| Provider | Purpose |
|---|---|
| Supabase | Cloud database and file storage |
| Vercel | Application hosting and content delivery |
| Anthropic | AI model provider used to process content you submit to the assistant |
| AI model provider used to process content you submit to the assistant | |
| OpenAI | Speech-to-text processing for recordings you create |
| Stripe | Payment processing |
| Resend | Transactional email delivery |
| PostHog | Product usage analytics |
| Sentry | Application error monitoring |
6. Secure Development
Changes to the Service are reviewed before release and must pass an automated test suite. Dependencies are reviewed and updated. Application errors in production are monitored; where diagnostic session recordings are captured, text content is masked and media is excluded.
7. Compliance Status
We do not currently hold a SOC 2 report, ISO/IEC 27001 certification, or the report of an independent third-party security assessment, and we make no representation that we do. Customers whose procurement requirements include such attestations should take this into account.
8. Vulnerability Disclosure
We welcome reports of suspected security vulnerabilities. Please submit reports to security@ponderos.com with sufficient detail to reproduce the issue. We ask that you allow a reasonable period for remediation before any public disclosure, and that you do not access data belonging to any account other than your own or take any action that degrades the Service for other users.
We will acknowledge receipt promptly and will keep you informed until the matter is resolved. We do not operate a paid bug bounty program, and will provide attribution on request.
If you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorized, we will not initiate or recommend legal action against you in connection with it under the Computer Fraud and Abuse Act, the DMCA’s anti-circumvention provisions, or any similar law, and we will not treat it as a breach of our Terms of Service. If a third party initiates legal action against you in connection with research conducted in compliance with this policy, we will make that authorization known.
9. Incident Response
In the event of a security incident affecting customer data, we will notify affected customers without undue delay and in accordance with applicable law, and will describe the nature of the incident, the data affected, and the measures taken in response.