Security

An overview of the measures protecting customer data, and how to report a vulnerability.

Effective August 22, 2026

This page summarizes the security measures applied to the PonderOS service by PonderOS Labs LLC. It is provided for information only, does not form part of any contract, and does not create any warranty or representation.

1. Data Protection

Customer data is encrypted in transit using industry-standard transport-layer security, and is encrypted at rest by our infrastructure providers. Access to production systems is limited to personnel who require it in order to operate and support the Service, and is used only for that purpose.

2. Access Control and Isolation

Each customer’s data is logically isolated from that of every other customer, and access is enforced at the data layer on the basis of authenticated identity. Within a customer’s account, permissions are governed by workspace roles that determine which users may view and modify content.

3. Authentication

Authentication is performed through Google sign-in or a one-time code delivered to the registered email address. We do not store passwords. Sessions are maintained using secure, HTTP-only cookies, and all application interfaces require authentication. Programmatic access credentials are stored only in hashed form, are displayed once on creation, and may be revoked by the customer at any time. Authentication and application interfaces are subject to rate limiting.

4. Availability and Backup

Our infrastructure providers perform automated, encrypted backups of production data on a regular schedule for disaster-recovery purposes. Backups are not a substitute for customer-controlled copies; the Service provides a self-service export function permitting customers to retain their own copies of their data in standard formats, and documents retain a revision history within the Service.

5. Service Providers

We engage the service providers listed below, in each case under written terms requiring appropriate technical and organizational security measures. The same list appears in our Privacy Policy.

ProviderPurpose
SupabaseCloud database and file storage
VercelApplication hosting and content delivery
AnthropicAI model provider used to process content you submit to the assistant
GoogleAI model provider used to process content you submit to the assistant
OpenAISpeech-to-text processing for recordings you create
StripePayment processing
ResendTransactional email delivery
PostHogProduct usage analytics
SentryApplication error monitoring

6. Secure Development

Changes to the Service are reviewed before release and must pass an automated test suite. Dependencies are reviewed and updated. Application errors in production are monitored; where diagnostic session recordings are captured, text content is masked and media is excluded.

7. Compliance Status

We do not currently hold a SOC 2 report, ISO/IEC 27001 certification, or the report of an independent third-party security assessment, and we make no representation that we do. Customers whose procurement requirements include such attestations should take this into account.

8. Vulnerability Disclosure

We welcome reports of suspected security vulnerabilities. Please submit reports to security@ponderos.com with sufficient detail to reproduce the issue. We ask that you allow a reasonable period for remediation before any public disclosure, and that you do not access data belonging to any account other than your own or take any action that degrades the Service for other users.

We will acknowledge receipt promptly and will keep you informed until the matter is resolved. We do not operate a paid bug bounty program, and will provide attribution on request.

If you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorized, we will not initiate or recommend legal action against you in connection with it under the Computer Fraud and Abuse Act, the DMCA’s anti-circumvention provisions, or any similar law, and we will not treat it as a breach of our Terms of Service. If a third party initiates legal action against you in connection with research conducted in compliance with this policy, we will make that authorization known.

9. Incident Response

In the event of a security incident affecting customer data, we will notify affected customers without undue delay and in accordance with applicable law, and will describe the nature of the incident, the data affected, and the measures taken in response.