Security and data
How Pondros protects your workspace: what it can see, where data lives, who can reach it, and where our security programme stands.
In Slack
- Pondros posts only as Pondros. It can’t post, edit or delete as a person, and only ever deletes its own messages.
- It joins your public channels at install and reads messages where it’s present. It can’t join a private channel unless someone invites it.
- It reads a person’s own DMs only if that person turns DM watching on, and never DMs between other people.
- Every permission is listed on Slack’s approval screen, and removing the app revokes them all. See What the Slack app can access.
Your data
- Stays in the United States. Our application servers and database run in US regions. We share exact regions with customers who need them for a security review.
- Encrypted in transit over HTTPS/TLS.
- Kept only as long as needed: copies of Slack messages for 120 days, your board until you delete it. See Data retention and deletion.
Who can reach it
- Each workspace is isolated from every other. A Slack workspace connects to one Pondros workspace.
- Guests see only what’s shared with them.
- Connected apps are read-only until someone switches them to Read & write. See How connecting works.
AI
Pondros runs on Anthropic’s Claude models under commercial terms that say Anthropic “may not train models on Customer Content from Services.” We don’t train models on your data either. See AI models and training.
Certifications
SOC 2 Type II: in progress.We aren’t certified today, and would rather say so than imply otherwise. If your procurement needs a security questionnaire, we’ll complete it; ask on a demo or at hey@pondros.com. A DPA is available on request.