Security & data / SANDR
Trust starts before the pilot.
This page describes the marketing website and the questions we resolve before any venue or employee data enters a guided programme or pilot.
Read the notice01 / Security & data
Website boundary
The public website is isolated from the SANDR product workspace. It uses an allowlisted promoted route manifest, restrictive browser security headers, request-size and method limits, rate-limited lead intake, release health reporting, and automated checks for private-file exposure. Unpublished preview routes remain outside public discovery and are no-indexed.
02 / Security & data
Before a programme or pilot receives data
Each connected account must define the organisations involved, permitted data, purpose, access roles, retention, deletion or export path, service providers, incident contact, and any international transfer process required. The marketing form is not a channel for business files, staff reports, proofs, passwords, or sensitive personal data.
03 / Security & data
Which AI services handle customer data
SANDR will identify the AI and hosting providers used for a pilot and document the settings and agreements that apply to customer data. We will not treat a broad website statement as a substitute for the pilot-specific data-processing agreement. Questions about AI training, retention, and provider access should be resolved in writing before onboarding.
04 / Security & data
Access and least privilege
Website enquiries are delivered only to the people and providers needed to respond. Pilot access must be role-scoped and reviewed with the customer. Credentials and secrets must not be submitted through the public form.
05 / Security & data
If something goes wrong
Security-related errors are recorded with the product version so the affected release can be contained or reversed. A pilot agreement will define the incident contact and notification process that fits the agreed data and service.
06 / Security & data
Report a vulnerability
Email gm@sandr-ai.com with the subject “Security report”. Include the affected URL, a concise description, and safe reproduction steps. Do not access other people’s data, disrupt service, or publish sensitive detail before we have had a reasonable opportunity to investigate.
Security questions
Ask before you share.
We can explain the website boundary and discuss the data process for a specific pilot.