SunDeer — custom software for creative businesses SunDeer
What we build How we work Our work Let's talk

Legal

Security

Last updated: June 2026

On this page
  • Our approach
  • Your data & engagements
  • AI & your data
  • Infrastructure
  • Application security
  • Access controls
  • Incident response
  • People
  • Third parties
  • Responsible disclosure
  • Contact

Our approach

We are a small team that builds custom software, often working with data that matters to the businesses we serve. Security is part of how we build, not a badge we bolt on.

We don't yet hold formal certifications like SOC 2. What follows is what we actually do — described plainly, with no claims we can't stand behind.

Your data & engagements

We collect as little as we can and keep only what an engagement needs. For the data we do handle:

  • We sign a data processing agreement with you before handling your data
  • Your data is kept separate from other clients' work
  • Where the work allows, your data stays in your own environment rather than ours
  • Connections are encrypted, and production data is never exposed to the public internet
  • We apply retention schedules and delete your data when it's no longer needed, or when you ask

Our backups are encrypted and tested so that, if we ever need them, we know they work.

AI & your data

The systems we build ground their answers in your own material — your Archive — using retrieval, so responses stay rooted in your work rather than guesswork.

We never use your data to train models. When a request runs, the relevant material is sent to a language-model provider only to answer that request, and for nothing else. We are working to formalise zero-retention and no-training terms with the providers we use, and we'll keep this page honest about where that stands.

Infrastructure

Our production infrastructure runs on a global edge network, which gives us:

  • DDoS protection and traffic filtering at the network edge
  • A web application firewall with managed rulesets
  • Encrypted connections for all traffic
  • Isolated execution per request, distributed with no single point of failure

Application security

Security is built into how we write and ship code:

  • Code is reviewed by another engineer before it reaches production
  • Dependencies are kept current and watched for known vulnerabilities
  • Automated security scanning runs in our pipeline on every change
  • We follow OWASP guidance for web application security
  • API endpoints are authenticated; input is validated and output encoded to prevent injection

Access controls

We work to the principle of least privilege:

  • Production access is limited to the people whose role requires it
  • Multi-factor authentication is required across our internal systems and cloud providers
  • Access uses keys rather than passwords, and privileged access is logged
  • Access is reviewed and revoked promptly when a role changes or someone leaves

Incident response

We keep a documented plan covering detection, containment, eradication, and recovery. If an incident affects your data:

  • We'll notify you within 72 hours of confirming a breach
  • We'll give you a written summary of what happened, its scope, and what we did about it
  • We'll cooperate with any regulatory notifications the law requires

To report a suspected incident, email security@sundeer.ai.

People

Everyone on the team does security-awareness training when they join and periodically afterward, and is bound by a confidentiality agreement.

Third parties

We keep the number of third-party services we rely on small, and share only what each one needs to do its job.

Responsible disclosure

Found a vulnerability? We welcome reports from the security research community.

Email security@sundeer.ai with the details. We ask that you give us reasonable time to investigate and fix the issue before disclosing it publicly, and that you avoid accessing, changing, or deleting data that isn't yours.

We'll acknowledge your report within 3 business days and keep you posted on our progress.

We won't pursue legal action against researchers who act in good faith and follow responsible disclosure.

Contact

For security questions, vulnerability reports, or anything about how we work:

  • Email: security@sundeer.ai
  • General: sundeer.ai
SunDeer

Custom software for creative businesses, built on craft.

Bespoke · Private · Secure
Explore
  • What we build
  • How we work
  • Contact
  • Our work
Legal
  • Privacy Policy
  • Terms of Service
  • Security

© 2026 SunDeer — All rights reserved.