Legal
Security
Last updated: June 2026
Our approach
We are a small team that builds custom software, often working with data that matters to the businesses we serve. Security is part of how we build, not a badge we bolt on.
We don't yet hold formal certifications like SOC 2. What follows is what we actually do — described plainly, with no claims we can't stand behind.
Your data & engagements
We collect as little as we can and keep only what an engagement needs. For the data we do handle:
- We sign a data processing agreement with you before handling your data
- Your data is kept separate from other clients' work
- Where the work allows, your data stays in your own environment rather than ours
- Connections are encrypted, and production data is never exposed to the public internet
- We apply retention schedules and delete your data when it's no longer needed, or when you ask
Our backups are encrypted and tested so that, if we ever need them, we know they work.
AI & your data
The systems we build ground their answers in your own material — your Archive — using retrieval, so responses stay rooted in your work rather than guesswork.
We never use your data to train models. When a request runs, the relevant material is sent to a language-model provider only to answer that request, and for nothing else. We are working to formalise zero-retention and no-training terms with the providers we use, and we'll keep this page honest about where that stands.
Infrastructure
Our production infrastructure runs on a global edge network, which gives us:
- DDoS protection and traffic filtering at the network edge
- A web application firewall with managed rulesets
- Encrypted connections for all traffic
- Isolated execution per request, distributed with no single point of failure
Application security
Security is built into how we write and ship code:
- Code is reviewed by another engineer before it reaches production
- Dependencies are kept current and watched for known vulnerabilities
- Automated security scanning runs in our pipeline on every change
- We follow OWASP guidance for web application security
- API endpoints are authenticated; input is validated and output encoded to prevent injection
Access controls
We work to the principle of least privilege:
- Production access is limited to the people whose role requires it
- Multi-factor authentication is required across our internal systems and cloud providers
- Access uses keys rather than passwords, and privileged access is logged
- Access is reviewed and revoked promptly when a role changes or someone leaves
Incident response
We keep a documented plan covering detection, containment, eradication, and recovery. If an incident affects your data:
- We'll notify you within 72 hours of confirming a breach
- We'll give you a written summary of what happened, its scope, and what we did about it
- We'll cooperate with any regulatory notifications the law requires
To report a suspected incident, email security@sundeer.ai.
People
Everyone on the team does security-awareness training when they join and periodically afterward, and is bound by a confidentiality agreement.
Third parties
We keep the number of third-party services we rely on small, and share only what each one needs to do its job.
Responsible disclosure
Found a vulnerability? We welcome reports from the security research community.
Email security@sundeer.ai with the details. We ask that you give us reasonable time to investigate and fix the issue before disclosing it publicly, and that you avoid accessing, changing, or deleting data that isn't yours.
We'll acknowledge your report within 3 business days and keep you posted on our progress.
We won't pursue legal action against researchers who act in good faith and follow responsible disclosure.
Contact
For security questions, vulnerability reports, or anything about how we work:
- Email: security@sundeer.ai
- General: sundeer.ai