Security at Bondi

Controls that follow your data, people, automations, and AI

Last Updated: August 3, 2026

This page describes Bondi’s current security approach. It is not a certification, audit report, or contractual service-level agreement. Enterprise security commitments, data-location requirements, support channels, and uptime terms apply only when they are included in a signed agreement.

1. Security model

Bondi is built as a multi-tenant control plane with isolated customer data infrastructure. Each customer receives a dedicated PostgreSQL database, while application access is mediated through authenticated services and workspace-aware authorization.

The product separates human users, Portal identities, AI Agents, Automations, API Keys, Service Accounts, and Partner access. These identity types are not treated as interchangeable credentials.

2. Identity and access

Bondi provides:

  • authenticated user and service access;
  • role-, screen-, and action-level permissions in Standard;
  • record- and field-level permissions, custom roles, approval flows, and Service Accounts in Pro;
  • revocable, user-specific MCP access in Pro;
  • audit records for sensitive account, access, and system changes; and
  • SSO/SCIM, IP allowlists, and contract-specific access requirements in Enterprise.

Customers control who receives access to their account. A verified Partner seat must be granted by the customer, is recorded in the audit history, and can be revoked by the customer.

3. Data and secrets

  • Network traffic is served over HTTPS/TLS.
  • Managed storage and database providers encrypt stored data using their platform controls.
  • Application secrets are kept outside source code and injected through managed secret stores or protected runtime bindings.
  • Customer files, database data, credentials, and workflow configuration are separated by tenant and workspace context.
  • Production credentials are not intended to be reused for development or manual test executions.

Customers should not place credentials in free-text fields, prompts, source code, or unprotected documents. API Keys and Service Accounts should be scoped to the minimum access required and rotated when their purpose or owner changes.

4. Infrastructure and reliability

Bondi uses managed infrastructure across Google Cloud, Cloudflare, Neon, and supporting providers. Current components include:

  • Google Cloud runtime services, secrets, monitoring, and archive operations;
  • Cloudflare edge services, Workers, and object storage;
  • dedicated PostgreSQL databases on Neon; and
  • infrastructure-as-code for repeatable environment configuration.

The exact provider or region can change as the platform evolves. Enterprise customers may contract for a specific region, dedicated infrastructure, or additional controls.

Production operations include health monitoring, structured logs, controlled deployment, backup and restore workflows, and incident investigation procedures. Pro includes separate Development and Production environments, version history, controlled publication, and rollback. Contractual uptime targets and service credits are available only through an Enterprise agreement.

5. AI, automation, and integrations

AI does not bypass the product’s authorization model. AI Agents, Automations, integrations, MCP clients, and Service Accounts are assigned explicit identities or grants and operate within the permissions and system boundaries available to them.

Sensitive actions can be placed behind approval flows. Integration secrets are stored separately from workflow configuration. Execution records support investigation of automation behavior, retries, failures, and external calls.

6. Retention, export, and deletion

Active customer data is retained while the account is in service and as required to provide the product. When a Trial expires or a subscription ends, Bondi keeps viewing, billing, and export access available for 30 days while write operations, AI, Production Automations, and Portals are stopped. The account is then queued for deletion unless law or a signed agreement requires a different period.

Backups and provider-level recovery copies can remain for a limited period under their lifecycle policies and are not restored for ordinary product use after deletion. Legal holds and fraud, tax, or security records may be retained when required by law or legitimate compliance needs.

7. Independent assurance

Bondi does not claim a security certification merely because an infrastructure provider holds one. Current Bondi audit reports, penetration-test summaries, questionnaires, or compliance commitments are provided only when available and, where appropriate, under NDA through the Enterprise review process.

8. Shared responsibility

Customers are responsible for:

  • granting and revoking user, Partner, Portal, API, and Service Account access;
  • configuring roles, record rules, approval flows, and integration scopes;
  • protecting computers and devices used with Bondi Desktop and approved local device actions;
  • reviewing generated systems, automations, AI instructions, and changes before Production; and
  • exporting records required by their own retention or regulatory obligations.

9. Reporting a vulnerability

Please follow our Responsible Disclosure Policy or email security@heybondi.com. Include enough detail to reproduce the issue, but do not access, modify, or retain data that does not belong to you.

For privacy questions, contact privacy@heybondi.com. For Enterprise security reviews, contact us.