What is in place today, plainly. We would rather tell you where we are than imply a maturity we have not reached — if a control below matters to your purchase, ask us and we will answer specifically.
rendr is not SOC 2 certified today, and does not claim to be. We are not ISO 27001 certified either. If you need an audited report to buy, tell us — it changes our roadmap priority, and we can talk about what we can evidence in the meantime (architecture review, a security questionnaire, a DPA, and the practices below).
The application runs on Google Cloud Run in the United States (us-central1). Project data and generated media are stored on Google Cloud infrastructure. Data is encrypted in transit with TLS, and at rest by the storage layer.
Sessions use a signed, HttpOnly, SameSite=Lax cookie, served with Secure in production. Passwords are stored hashed, never in plain text. Admin surfaces are gated separately from ordinary accounts.
Access to production systems is limited to the people who operate the service. Provider API keys are held as environment configuration and are not committed to source control.
Every project save keeps a version history, and recent versions are retained so a bad save can be recovered. You can export your account and every project you own as JSON from the app at any time. Deleting a project removes it from active systems; see the Privacy Policy for retention detail.
The third parties that can process customer data are listed on the Subprocessors page, with what each one does and what it can see.
Email hello@saucemedia.us with “Security” in the subject. Please give us enough detail to reproduce the issue, and give us a reasonable window to fix it before disclosing publicly. We will not pursue legal action against good-faith research that respects user privacy and avoids service degradation or data destruction.
If customer data is affected by a security incident, we will notify affected accounts by email with what we know, what we have done, and what you should do.
← Back to rendr.gg