Security

Last updated 29 August 2026 · rendr.gg, operated by Sauce Media

What is in place today, plainly. We would rather tell you where we are than imply a maturity we have not reached — if a control below matters to your purchase, ask us and we will answer specifically.

Certifications — where we actually stand

rendr is not SOC 2 certified today, and does not claim to be. We are not ISO 27001 certified either. If you need an audited report to buy, tell us — it changes our roadmap priority, and we can talk about what we can evidence in the meantime (architecture review, a security questionnaire, a DPA, and the practices below).

Hosting and data location

The application runs on Google Cloud Run in the United States (us-central1). Project data and generated media are stored on Google Cloud infrastructure. Data is encrypted in transit with TLS, and at rest by the storage layer.

Authentication

Sessions use a signed, HttpOnly, SameSite=Lax cookie, served with Secure in production. Passwords are stored hashed, never in plain text. Admin surfaces are gated separately from ordinary accounts.

Access

Access to production systems is limited to the people who operate the service. Provider API keys are held as environment configuration and are not committed to source control.

Data retention and deletion

rendr keeps periodic project recovery snapshots, generally no more than one every ten minutes, with up to 100 snapshots per project. You can download account profile, workspace, document-list, and credit-history data from Settings, and export each project separately from its editor. Deleting a project removes it from the active project list and places it in recoverable Trash for 30 days; see the Privacy Policy for retention detail.

Subprocessors

The third parties that can process customer data are listed on the Subprocessors page, with what each one does and what it can see.

Reporting a vulnerability

Email hello@saucemedia.us with “Security” in the subject. Please give us enough detail to reproduce the issue, and give us a reasonable window to fix it before disclosing publicly. We will not pursue legal action against good-faith research that respects user privacy and avoids service degradation or data destruction.

Incidents

If customer data is affected by a security incident, we will notify affected accounts and regulators as required by applicable law, with what we know, what we have done, and what you should do.

← Back to rendr.gg