Security

Last updated 31 July 2026 · rendr.gg, operated by Sauce Media
⚠ Draft starting point — review and finalize this copy with counsel, and confirm the entity name, contact details and any figures, before relying on it.

What is in place today, plainly. We would rather tell you where we are than imply a maturity we have not reached — if a control below matters to your purchase, ask us and we will answer specifically.

Certifications — where we actually stand

rendr is not SOC 2 certified today, and does not claim to be. We are not ISO 27001 certified either. If you need an audited report to buy, tell us — it changes our roadmap priority, and we can talk about what we can evidence in the meantime (architecture review, a security questionnaire, a DPA, and the practices below).

Hosting and data location

The application runs on Google Cloud Run in the United States (us-central1). Project data and generated media are stored on Google Cloud infrastructure. Data is encrypted in transit with TLS, and at rest by the storage layer.

Authentication

Sessions use a signed, HttpOnly, SameSite=Lax cookie, served with Secure in production. Passwords are stored hashed, never in plain text. Admin surfaces are gated separately from ordinary accounts.

Access

Access to production systems is limited to the people who operate the service. Provider API keys are held as environment configuration and are not committed to source control.

Data retention and deletion

Every project save keeps a version history, and recent versions are retained so a bad save can be recovered. You can export your account and every project you own as JSON from the app at any time. Deleting a project removes it from active systems; see the Privacy Policy for retention detail.

Subprocessors

The third parties that can process customer data are listed on the Subprocessors page, with what each one does and what it can see.

Reporting a vulnerability

Email hello@saucemedia.us with “Security” in the subject. Please give us enough detail to reproduce the issue, and give us a reasonable window to fix it before disclosing publicly. We will not pursue legal action against good-faith research that respects user privacy and avoids service degradation or data destruction.

Incidents

If customer data is affected by a security incident, we will notify affected accounts by email with what we know, what we have done, and what you should do.

← Back to rendr.gg