Trust, stated plainly.
What was said on a client call is the most sensitive thing your team handles. Here is exactly how we treat it, and where our programme still has road ahead.
Private by design
Your meetings stay yours.
What was said in the room, protected at every step.
On your device by default
Capture and transcription run locally. Only the tasks you approve are synced to your workspace.
Encrypted in transit and at rest
Everything travels over TLS, and the transcripts, notes, and summaries we store are encrypted in our database.
Credentials in your keychain
Your workspace and transcription keys live in your operating system's keychain, never in plain text.
Isolated, and signed
Each workspace is private. We never silently join you to someone else's. The Mac app is Apple-notarized.
Your data stays in the United States
Our application servers run in the United States, and the database that holds your transcripts, notes, and tasks runs in a US region on AWS. Nothing about your meetings is stored outside the US. We share the exact regions with customers who need them for a security review.
We don't host our own models
Speech-to-text and note-writing run on commercial APIs rather than models we train ourselves. That means your meetings are processed under those vendors' commercial terms, not used to build a product of ours.
Anthropic can't train on your content
Anthropic's commercial terms state plainly that "Anthropic may not train models on Customer Content from Services." Your notes and summaries are not training data.
Certifications
SOC 2 Type II: in progress. We are not certified today, and we would rather tell you that than imply otherwise. The controls described on this page are in place now; the audit is the part that isn’t finished.
If your procurement process needs a security questionnaire completed, we’ll complete it. Ask on your demo.
What Pondros can see in Slack
- Pondros joins your public channels when it is installed, so that what people promise in them can be caught. That is a workspace setting you can turn off, and it never joins a private channel unless somebody invites it.
- It reads direct messages it is part of — the ones between a person and Pondros. It cannot read direct messages between other people: Slack grants no app that access, and we do not ask for it.
- It reads channel history, your workspace’s member directory and email addresses, and files shared where it is present. History is what lets it catch a commitment made an hour before anyone thought to ask.
- It can post, reply, react, run its slash command, and create the #pondros channel. It holds no permission to delete a message, to remove a person, or to act as anyone — everything it posts is posted as Pondros.
- Slack lists every one of these permissions on the approval screen before you install, and an admin can revoke all of them at any time by removing the app.
Data in transit and at rest
- All traffic to our website and backend is encrypted over HTTPS/TLS.
- Transcripts and notes stay on your device by default. Only the segments and tasks you approve are synced to your workspace.
- The meeting content we do store (transcripts, notes, and AI summaries) is encrypted at rest, so a leaked database row doesn't expose what was said.
- App credentials (your workspace key, any transcription key) are stored encrypted in your operating system's keychain, never in plain text.
Access and isolation
- Each workspace is isolated. New sign-ups get their own private workspace, and we don't silently join you to anyone else's based on an unverified email address.
- Backend access to meeting endpoints is authenticated with a per-device key stored only as a hash on our servers, so a leaked row can't be replayed.
- Sensitive endpoints are rate-limited and usage-capped to limit abuse.
Code signing
- The macOS app is signed with an Apple Developer ID and notarised by Apple, so your Mac can verify it hasn't been tampered with before it runs.
Subprocessors
We rely on a small set of infrastructure and processing partners, each with its own security and data-protection commitments and each given only what its job requires. Our Privacy Policy names them, and the current list forms part of the data-processing agreement we sign with Enterprise customers.
Reporting a vulnerability
If you believe you’ve found a security issue, email hey@pondros.com. We’ll acknowledge your report and work with you on a fix. Please give us a reasonable chance to address it before any public disclosure.
Bring your security questions.
We'd rather answer them before you buy than after.
Free to start, no credit card · no bot joins your calls