Skip to content
sundr
Results How it works Guarantee Pricing Docs Writing Free audit

Security

Last updated 9 October 2026.

This page describes how Sundr handles your data today: where it goes, how it is protected, how long we keep it, and what is not in place yet. If anything here is unclear or out of date, email [email protected].

How data moves

Savings Audit

  1. You upload a log export to sundr.ai, or connect a log platform (Langfuse, LangSmith, Braintrust or Helicone) with an API key. Sundr stores the upload or the key encrypted. A key is read once by the worker, which deletes it before pulling up to 30,000 calls from the last two weeks; the pulled calls are then stored encrypted like an upload. Sundr emails you a confirmation link through Resend.
  2. When you click the link, the audit joins a queue and runs. A sample of up to 60 logged calls goes to Anthropic, whose Claude model drafts questions about your task.
  3. The text of each logged call goes, with those questions, to two decision-model providers: TypeSafe's Jev model through OpenRouter, and Cloudflare's Clef model on Workers AI. Large uploads may be sampled first, to keep the audit within its cost limit.
  4. Sundr writes the report, then deletes the upload and the cached model answers. The report holds summary numbers and the questions Sundr asked. It does not contain your logged calls.
  5. We email you the report link. Anyone with the link can open the report, so share it only with people who should see it.

Proxy (proxy.sundr.ai)

  • Every request carries your workspace key in X-Sundr-Key. Sundr checks it against a stored hash.
  • Requests without X-Sundr-Task, and streaming requests, are forwarded to your LLM provider unchanged. Sundr does not store their content.
  • Until a task is in takeover, each judgment call is forwarded to your LLM provider and its answer is returned unchanged.
  • For judgment calls, Sundr stores the input text and the verdict. It adds token counts, model name and latency for calls your LLM answers, and a confidence score for calls Sundr answers. It also stores the task's system prompt as the task description.
  • To certify a task, Sundr fits a model on that task's stored calls. Their text goes to the decision-model providers, and a sample of up to 60 goes to Anthropic to draft questions.
  • In takeover, the text of each judgment call goes to the decision-model providers. Sundr answers the call when its score clears the certified threshold. Otherwise the call goes to your LLM as before. A share of the calls Sundr answers is also sent to your LLM, with your key, to check Sundr's answers.

Dashboard

  • You sign in with a single-use link emailed to a member of your workspace (valid 15 minutes; only its hash is stored), through your company's OpenID Connect single sign-on if it's set up for your email domain, or with your workspace key. Sundr then sets a session cookie signed with HMAC-SHA256.
  • Single sign-on uses the authorization code flow. Sundr checks the ID token's RS256 signature against your identity provider's published keys, its issuer, audience, expiry and nonce, and that the email is verified and at your configured domain. The client secret is stored encrypted.
  • The cookie is HttpOnly and SameSite=Strict, is only sent over HTTPS, and expires after 30 days. Signing out deletes it.

Encryption

In transit

  • All traffic to sundr.ai and proxy.sundr.ai uses TLS. Cloudflare terminates TLS, then connects to our Fly.io server over TLS and checks its certificate (Cloudflare's "Full (strict)" mode).
  • Cloudflare decrypts each request at its edge and encrypts it again on the way to Fly.io. So uploads and proxy requests, including their headers, pass through Cloudflare.
  • Sundr's calls to OpenRouter, Cloudflare Workers AI, Anthropic, Resend and your LLM provider all use HTTPS.

At rest

  • Uploaded logs are encrypted by the app with Fernet (AES-128 in CBC mode, with an HMAC-SHA256 check). The key is stored as a Fly.io secret, not on the disk with the data.
  • Everything Sundr stores is on one Fly.io volume, which Fly.io encrypts at rest. That covers the databases (audit records, workspaces, tasks, proxy call logs) and reports. The app does not encrypt these a second time.
  • Some export formats are written to a temporary file on the same volume while they are read, and deleted straight after.

How long we keep data

DataKept
Uploaded logsDeleted when the report is written, or if the audit fails. Deleted within 2 days if you never confirm the audit.
Cached decision-model answers for an auditDeleted when the report is written.
ReportsDeleted after 30 days.
Audit records: email address, the settings you entered, task name, number of calls, summary numbersKept so we can reply to you. Ask and we'll delete them.
Proxy call logsDeleted after 30 days.
Workspaces, task settings, system prompts, certificates and task modelsKept while your workspace is open. Ask and we'll delete them.
Volume snapshotsFly.io takes daily snapshots of the volume and keeps them for 5 days by default. Deleted data can remain in a snapshot until it expires.

Your data is not used to train shared or general-purpose models. The only models fitted on it are the per-task models that answer your own calls.

Who can access production

  • Sundr runs on Fly.io. DNS and TLS are managed in Cloudflare. Only the founder has access to those accounts and to the production machine.
  • Accounts with production access must use two-factor authentication.
  • We look at customer data only to run the service, to fix a problem, or when you ask us to.
  • Sundr's own secrets (the encryption key, the key that signs dashboard sessions, and its provider API keys) come from Fly.io secrets. They are not in the code repository.

Keys

  • Your LLM provider key travels with each proxy request and is forwarded to your provider. Sundr never stores or logs it. It is held in memory only while the request, or the background check it triggers, is running.
  • Workspace keys are made from 32 random bytes and shown once. Sundr stores only their SHA-256 hash, so we can't recover a lost key. We can issue a new one. If a key leaks, email us and we'll replace it.
  • Report and confirmation links each contain a token made from 32 random bytes.

Incidents

If you think your data or a Sundr key has been exposed, email [email protected]. If we confirm a breach that affects your data, we will tell you by email without undue delay, and within 72 hours of becoming aware of it.

What is not in place yet

  • There is no SOC 2 report. SOC 2 Type I readiness work is planned.
  • No third-party penetration test has been done.
  • Everyone who can sign in to a workspace's dashboard has the same access. There are no roles yet, and SAML isn't supported (OpenID Connect is).
  • Sundr runs on one machine in one region (Ashburn, Virginia, US). There is no standby machine or second region, so an outage affects the site, the dashboard and the proxy together.
  • The Data Processing Addendum is a draft for counsel review. It is not yet offered for signature.

Reporting a vulnerability

Email [email protected]. Mail to that address reaches the team. Please include the steps to reproduce the issue and what you were able to access. We aim to reply within three business days, and we'll tell you when it is fixed.

  • Test only against your own workspace and your own audits.
  • Don't access, change or keep other people's data. If you reach some by accident, stop and tell us.
  • Don't run denial-of-service tests or send spam.
  • Give us reasonable time to fix the issue before you publish it.

We won't take legal action against research done in good faith under these rules. There is no paid bug bounty.

See also: subprocessors, privacy, terms.

sundr

Uploaded logs are encrypted at rest and deleted as soon as your report is ready. Reports are deleted after 30 days.

Docs Writing Agent setup Dashboard Privacy Terms Security Subprocessors [email protected]