Trust, stated plainly.
What was said on a client call is the most sensitive thing your team handles. Here is exactly how we treat it — and where our programme still has road ahead.
Private by design
Your meetings stay yours.
What was said in the room — protected at every step.
On your device by default
Capture and transcription run locally. Only the tasks you approve are synced to your workspace.
Encrypted in transit and at rest
Everything travels over TLS, and the transcripts, notes, and summaries we store are encrypted in our database.
Credentials in your keychain
Your workspace and transcription keys live in your operating system's keychain — never in plain text.
Isolated, and signed
Each workspace is private — we never silently join you to someone else's. The Mac app is Apple-notarized.
Your data stays in the United States
Our application servers run in Newark, New Jersey. The database that holds your transcripts, notes, and tasks runs in AWS us-east-2 in Ohio. Nothing about your meetings is stored outside the US.
We don't host our own models
Speech-to-text and note-writing run on commercial APIs — Deepgram and Anthropic — rather than models we train ourselves. That means your meetings are processed under those vendors' commercial terms, not used to build a product of ours.
Anthropic can't train on your content
Anthropic's commercial terms state plainly that "Anthropic may not train models on Customer Content from Services." Your notes and summaries are not training data.
Certifications
SOC 2 Type II — in progress. We are not certified today, and we would rather tell you that than imply otherwise. The controls described on this page are in place now; the audit is the part that isn’t finished.
If your procurement process needs a security questionnaire completed, we’ll complete it — ask on your demo.
Data in transit and at rest
- All traffic to our website and backend is encrypted over HTTPS/TLS.
- Transcripts and notes stay on your device by default — only the segments and tasks you approve are synced to your workspace.
- The meeting content we do store — transcripts, notes, and AI summaries — is encrypted at rest, so a leaked database row doesn't expose what was said.
- App credentials (your workspace key, any transcription key) are stored encrypted in your operating system's keychain, never in plain text.
Access and isolation
- Each workspace is isolated. New sign-ups get their own private workspace — we don't silently join you to anyone else's based on an unverified email address.
- Backend access to meeting endpoints is authenticated with a per-device key stored only as a hash on our servers, so a leaked row can't be replayed.
- Sensitive endpoints are rate-limited and usage-capped to limit abuse.
Code signing
- The macOS app is signed with an Apple Developer ID and notarised by Apple, so your Mac can verify it hasn't been tampered with before it runs.
Subprocessors
We rely on the following infrastructure and processing partners, each with its own security and data-protection commitments. See our Privacy Policy for what each one receives.
Reporting a vulnerability
If you believe you’ve found a security issue, email hey@pondros.com. We’ll acknowledge your report and work with you on a fix. Please give us a reasonable chance to address it before any public disclosure.
Bring your security questions.
We'd rather answer them before you buy than after.
Free to start · no bot joins your calls · Meet, Zoom, and Teams