Last updated: March 2026
We built Prior.Run with security-first principles. Here's how we protect your data at every step.
Uploaded images are re-encoded through Pillow before processing. Your raw files are never served directly or accessible via URL. This prevents metadata leaks and ensures only safe image data enters our pipeline.
Your designs are processed by automated analysis systems. We do not manually review uploaded designs as part of normal operations. Access to production data is restricted and logged.
Analysis results are retained as long as your account is active. You can request full data deletion at any time via your account settings or by contacting us.
Your designs are NOT used to train any models.
Your designs are processed by our proprietary analysis engine. Under our data processing policies, design inputs are used solely for generating your analysis and are not used to train or improve any models.
In the event of a security incident, we follow a structured response process:
We maintain request logging and monitoring to detect anomalies.
We regularly audit dependencies for known vulnerabilities using automated scanning tools. Security patches are applied promptly, and our infrastructure providers (Supabase, Render) maintain their own SOC 2 Type II compliance programs.
Access to production systems is restricted to authorized personnel only. We follow the principle of least privilege — each system component has only the permissions it needs. Database access is enforced through Row-Level Security (RLS) policies.
Analysis Engine
Design analysis — Inputs not used for training
Supabase
Database & auth — SOC 2 Type II compliant
Stripe
Payments — PCI DSS Level 1 certified
Render
Hosting — SOC 2 Type II compliant
We take security reports seriously. If you've found a security issue, please report it responsibly.
security@prior.run