Encrypted on disk
Sensitive data — private notes, integration tokens — is encrypted with AES-256 using keys unique to each deployment. If someone got the database file, they'd see ciphertext, not your data.
Sonar · Clearance Binder · File 47-N
Trust posture
Sonar reads collaboration patterns — not the words inside them. Every employee can pause, opt out, export, or delete their data. This binder lists the practices we ship and every company we share data with.
TL;DR for vendor reviewers
Commitments
Each is verifiable in product or in code.
We never read your message content
Sonar sees who messaged whom and when — never what was said. Same for PR diffs (we see who reviewed what, not the code itself). The text of any message stays where it was sent.
Every employee controls their own data
From your account page you can pause data collection (takes effect immediately), turn off any one source (Slack, GitHub, or calendar), export a copy of everything we have on you, or request deletion. Deletes get a 30-day grace window, then erase across every system.
Org-wide kill-switch
Any workspace owner can pause Sonar instantly — all processing halts within minutes. Useful during a layoff, an investigation, a regulatory request, or anything else where the right answer is "stop everything now and figure it out."
We watch ourselves for bias
Every signal Sonar fires is logged alongside the role and tenure of the person it fired for. If Sonar starts behaving differently for one group versus another, that shows up in a dashboard before it becomes a problem.
Every brief item shows its evidence
Every line in your morning brief links back to the actual Slack message, calendar event, or PR that triggered it. No AI claims without a source you can verify in one click.
Sonar never recommends firing or PIPs
If a brief or meeting summary tries to say "fire", "PIP", "terminate", or "underperformer", we reject it before it reaches you. Sonar surfaces patterns. Decisions about people stay with humans and HR.
Tamper-proof audit log
Every admin action — inviting someone, connecting an integration, flipping the kill-switch, exporting data — gets recorded in a log even Sonar staff can't edit or delete.
Data ages out automatically
By default we keep activity for 90 days, signals for one year, and meeting transcripts for 90 days. Each can be tuned per workspace. After the window, data is permanently deleted.
Compliance status
GDPR and CCPA practices are live. SOC 2 audit starts Q3 2026 — we won’t claim the report until it lands.
GDPR
DPA available on request; SCCs Module 2 (controller-to-processor) for EU/UK transfers; right-to-be-forgotten cascade implemented end-to-end.
CCPA
California residents can request deletion via /me; export bundle satisfies the right-to-know request.
SOC 2 Type I
SOC 2 Type I audit fieldwork is scheduled for Q3 2026. The auditor name will be published on /trust as soon as one is engaged. Type II observation period begins immediately after Type I lands.
SOC 2 Type II
Type II report targets Q3 2027.
Security practices
Nothing aspirational on this list.
Sensitive data — private notes, integration tokens — is encrypted with AES-256 using keys unique to each deployment. If someone got the database file, they'd see ciphertext, not your data.
Every connection uses modern TLS — between you and the app, between Sonar and Slack/GitHub/Anthropic, everywhere. No plaintext data moves over the wire.
Google SSO and magic-link email today. SAML/Okta single sign-on for organizations is on the roadmap.
Your data is isolated from every other customer's at the database level — not just enforced by the app. A bug in our code can't accidentally leak across organizations.
Every webhook from Slack, GitHub, Stripe, or our email provider is signed by them and verified by us before it can write anything. Replay attacks are blocked by a five-minute freshness window.
Email security@sonarwork.com. We respond inside one business day, push critical fixes inside seven days, and credit reporters publicly with their permission. External pen test is scheduled for Q3 2026 — we won't claim it until it's done.
If something goes wrong, we have written runbooks for the engineer on call and a 72-hour notification commitment for any confirmed breach affecting your data.
Subprocessors (10)
Four. That’s the list. Integrations like Slack, GitHub, and Calendar are data sources — Sonar reads from them, nothing flows back. You’ll get 30 days’ notice before any subprocessor is added or removed.
Claude is the AI model that writes your morning brief. We never send the contents of any message — only the structural facts (who, when, how often). Emails, phone numbers, and risky phrases are stripped before anything reaches the model.
Transactional + opt-in email delivery for morning briefs, invitations, and export-ready notifications. Bounces + complaints feed our suppression list.
Billing and subscription management. Your card number goes directly to Stripe — Sonar never sees it, stores it, or has access to it.
Product analytics — event names so we can see which features are used (e.g. "first brief sent", "integration connected"). Never message text. Browser-side capture (URL path, user agent, truncated IP) is gated on the cookie-consent banner.
Source data only — Sonar reads metadata about messages + reactions in channels you've connected. Slack does NOT receive any data from Sonar (one-way ingest).
Source data only — Sonar reads metadata about pull requests + reviews + commits in repos you've connected. GitHub does NOT receive any data from Sonar.
Source data only — Sonar reads meeting metadata (count, duration, attendee emails) from connected Google Workspace calendars. By default we never read meeting titles or descriptions.
Where the Sonar website and app actually run. Server logs are kept seven days and never contain message content.
Speech-to-text for the meeting bot. Used only when an admin enables the meeting bot and a host invites it to a call. Audio is streamed to Deepgram, transcribed, and discarded after we receive the text.
Object storage for short-lived encrypted meeting-bot audio blobs and customer data exports. Buckets are private; only Sonar can read them.
Questions & correspondence
Email security@sonarwork.com for security disclosures or compliance documents (DPA, SCCs, SOC 2 report when ready). Email privacy@sonarwork.com for GDPR / CCPA data subject requests if you can’t use the in-product /me page.
Last filed: . See also our quarterly precision report.