Security

Security

Last updated: 13 August 2026
This is a summary of our current practice, published so nothing on this site links nowhere. It is not yet a complete legal document — the full security page is being finalised. For anything not covered here, email david@buildwithsona.com and we will answer directly.

How your data is stored

Account data and the content you create are stored in Supabase (Postgres), protected by row-level security so one account cannot read another's rows. Traffic to this site and the studio is served over HTTPS.

Authentication

Sign-in is handled by Clerk. You receive a one-time code at your email address and enter it to sign in; we never see or store a password.

Access on our side

Sona is a small team. Administrative access to production data is limited to those who need it to operate the service, and admin write endpoints require a separate secret key that is not present in any client-side code.

What we do not do

Reporting a vulnerability

If you find a security issue, email david@buildwithsona.com with enough detail to reproduce it. We will acknowledge it and keep you updated on the fix. Please give us a reasonable chance to resolve the issue before disclosing it publicly.