Security and trust.

Your decisions are your most sensitive asset. Here is how Pronoa protects them today, and what comes next.

The controls listed here match the security annex of our published Data Processing Addendum, which was checked against production on 1 October 2026.

Four commitments.

The human authors every decision.

Decision statements, recommendations, and dissent are never machine-drafted into the record as yours. Authorship is a logged, timestamped event: Pronoa can prove the human made the call.

The model forgets.

Our AI provider, Anthropic, runs under zero data retention on our account, and customer content is never used to train its models.

Your record is yours.

Under our Terms, you own the data you bring and the briefs Pronoa produces for you. Pronoa uses only de-identified, aggregated usage data to improve the product, as the Terms describe.

Private by seat.

Each person’s decisions and briefs are visible only to them, including inside a team account. The company profile is the one thing a team shares.

In place today.

Encryption
Data is encrypted in transit over HTTPS, and at rest with AES-256, including backups. The database runs on Supabase, hosted on AWS in the US West region.
Separation
Customer data is logically separated. Decision records are restricted to their owner by row-level security, and organization records are scoped to the organization.
Files
Documents and briefs are held in private storage. No bucket is publicly readable, and brief downloads use time-limited signed links.
AI provider
Anthropic, under zero data retention and no training on customer content.
Telemetry
Model telemetry records timing, token counts, and cost, never the text of prompts or completions. Error monitoring scrubs long text, collects no default personal data, and keeps records for 30 days.
Payments
Card payments run on Stripe’s hosted checkout. Card numbers never touch Pronoa’s systems.
Sign-in
Email and password through the platform’s authentication service, with strictly necessary cookies only.
Internal access
Production systems and provider consoles are limited to named personnel (today, the CEO and one engineer), with multi-factor authentication on every account and written confidentiality obligations for everyone with access.
Backups
Daily encrypted database backups with a seven-day recovery window.
Change control
Changes are reviewed and validated in non-production before release, and each production deployment is verified.

What comes next.

The controls larger teams ask for arrive as an early 2027 addition, on US-region infrastructure.

  • Multi-factor authentication for user accountsEarly 2027
  • Fine-grained access controls and custom rolesEarly 2027
  • A complete audit trail of access, exports, and permissionsEarly 2027
  • Secure expiring links for sharing briefs with directors2027

Certification. Pronoa does not yet hold an independent security certification such as SOC 2. Until it does, we rely on the independent attestations of our infrastructure providers, and we answer security reviews directly.

The documents.

  • Data Processing Addendum

    How we process personal information in your data, including transfer terms and the full security annex.

  • Privacy Policy

    What we collect and why, retention, and our subprocessors.

  • Terms of Service

    The agreement for Individual and Team use, including data ownership.

Start with the call in front of you.

Your first decision is free: one real decision, all eighteen steps, a board-ready brief. The record is yours from the first run.

Work addresses receive their code right away. Personal addresses are reviewed by our team first. Already have an account? Sign in