Beta policy
Security & data handling
Pursuit information is commercially sensitive. This page describes the controls that are actually implemented today, and is deliberately conservative about what we do not claim.
Last updated: 17 August 2026
Using real deal data in the beta
Onden is designed to work on real pursuits. Use the customer, stakeholder and commercial information you are authorised to use so the analysis reflects the deal you are actually pursuing. Follow your organisation's policies. Do not enter credentials, payment-card data, special-category or highly sensitive personal data, regulated material, or information your organisation prohibits from being processed in third-party software.
Onden is in beta. The application uses authenticated accounts, server-side access controls and row-level data isolation, but Onden has not yet completed its own independent security certification.
Access and isolation
- Every opportunity route requires an authenticated session; there is no anonymous access to pursuit data.
- Records are owned by the account that created them and enforced with row-level access rules in the database, so one account cannot read another's data.
- Ownership is always derived from the verified server-side session, never from values supplied by the browser.
- Your plan is held on the server. It cannot be changed from the browser, and an admin preview mode changes presentation only.
Where processing happens
- AI analysis and document generation run on our servers behind authentication, not in your browser. Model calls are made from the server to a third-party AI provider.
- Customer research is restricted to the customer website saved on the opportunity. Before every request — including each redirect hop — the crawler rejects loopback, private and reserved addresses and hosts that resolve to them, and refuses redirects that leave that site.
- The browser cannot supply an arbitrary research target; the URL comes from your saved opportunity record.
- Provider API keys are held server-side and are never exposed to the browser.
What we keep out of the browser
Confidential customer and deal content is not written to browser local storage, URLs or analytics events. Product-usage analytics record interaction names only.
Deletion
You can delete an individual opportunity from its workspace, and delete all of your Onden data or close your account using “Delete my data” in the workspace sidebar. These actions are permanent, run server-side against your own records only, and remove the rows from the live database. Copies may remain for a period in our cloud provider's infrastructure-level backups.
What we do not claim
Onden holds no security certification today. We make no SOC 2, ISO 27001, HIPAA, PCI or formal GDPR-compliance claim, and we offer no data-residency guarantee, uptime commitment or contractual encryption guarantee beyond the protections our cloud infrastructure provides by default. A full audit trail and customer-managed retention controls are not implemented.
Onden runs on managed cloud infrastructure operated by our hosting and database providers, and inherits the platform-level controls they operate. Any certification held by a provider belongs to that provider and is not a certification of Onden.
Reporting a vulnerability
If you believe you have found a security issue, please report it through our contact page (or Help & feedback → Contact support inside the product) and avoid accessing data that is not yours. We will confirm receipt and prioritise it. See also the privacy notice.