Security is not a feature. It's our foundation.
We build security into how Superdegree stores, processes, and protects your recordings, connected applications, and generated content — from the moment data reaches us through processing, storage, and deletion.
Encrypted in transit and at rest
TLS 1.2+ protects data in transit, with industry-standard encryption at rest across our managed database and storage infrastructure.
Isolated by organisation
Row-level security and server-side ownership checks are designed to keep every organisation’s data separate.
We never hold your app passwords
You sign in to connected applications yourself. Authentication state is maintained in an isolated browser context so the Ask Agent can operate without Superdegree storing your app passwords in our database.
Infrastructure & Network Security
Superdegree runs on managed cloud infrastructure, including Vercel for the application layer, Supabase for our database and authentication, and Cloudflare R2 and AWS S3 for media storage and processing.
Traffic to and from Superdegree is encrypted in transit using TLS 1.2 or higher, with HTTPS enforced across the Service.
We use defensive browser and application security controls including protections against clickjacking, content-type sniffing, unnecessary referrer disclosure, and unauthorised browser permissions.
Protected requests are authorised on the server against the signed-in user and their organisation before Customer data is returned or protected actions are allowed to proceed.
Data Protection & Privacy
Data at rest is protected using industry-standard encryption across our managed database, backup, and object-storage infrastructure.
Our Postgres databases are organisation-scoped, with row-level security and server-side access controls designed to maintain isolation between customers and teams.
We practice data minimisation and process Customer Content to provide, secure, support, troubleshoot, and improve the Service.
We do not use Customer Content to train or fine-tune our own general-purpose artificial intelligence or machine-learning models unless expressly authorised by the customer.
Customer media is stored in private object storage and accessed through authenticated or signed, time-limited mechanisms rather than publicly accessible storage.
For more information about how we collect, process, retain, and share data, see our Privacy Policy.
Agent Sessions & Connected Apps
Ask Agent is currently in beta.
When the Ask Agent works inside one of your applications, it operates a browser hosted by our cloud-browser provider.
Your passwords stay out of Superdegree
We don’t ask you to provide your third-party application passwords to Superdegree.
Instead, you sign in yourself through a live view of the browser session. Authentication state may then be maintained in a persistent browser context so you don’t need to sign in again for every run.
Persistent browser contexts are scoped using Superdegree’s access-control mechanisms and are designed to prevent authentication state from being shared between unauthorised users, organisations, or applications.
You can request deletion of a stored browser context at any time, which removes the associated stored authentication state.
Our cloud-browser provider may retain browser-session recordings for up to 30 days for observability and debugging purposes. Authentication state is stored separately in the persistent browser context.
Application knowledge stays organisation-scoped
Information the Agent learns about an application — such as navigation information, interface structure, and workflow knowledge — is scoped to your organisation and is not used to serve another customer.
Guardrails for Agent actions
Agent runs include safeguards designed to identify and prevent certain destructive or irreversible actions, including actions such as deletion, purchases, signing out, or subscription cancellation.
You can also stop an Agent run in progress, which ends the active run and settles any unused portion of its reserved credits where applicable.
These safeguards reduce risk but cannot guarantee that an Agent will never take an unintended action.
An Agent takes real actions inside a real application. While Ask Agent remains in beta, we particularly recommend using test, sandbox, or demonstration accounts rather than production systems containing real Customer data wherever practical.
Transient Media Storage
Media — including source recordings, rendered videos, generated audio and images, and intermediate processing files — is stored in private object storage and accessed using authenticated or signed, time-limited URLs rather than public links.
Temporary artifacts created during rendering, compression, and other processing workflows are automatically deleted through storage lifecycle controls.
Depending on the workflow, temporary processing files may remain for up to 7 days before automatic deletion.
Customer Content retained as part of your projects follows the retention and deletion practices described in our Privacy Policy.
Authentication & Access Control
Authentication is handled through Supabase Auth, including email/password authentication and Google sign-in.
Sessions are maintained using secure authentication mechanisms designed to prevent unauthorised access.
Organisation-scoped access controls restrict access to protected resources according to the authenticated user, their organisation, and their permissions.
Server-side ownership and authorisation checks are performed before protected Customer resources or billable actions are made available.
Administrative access to production systems is restricted to authorised personnel and protected using appropriate access controls, including multi-factor authentication where supported.
Administrative and security-relevant activity is logged where appropriate for troubleshooting, security monitoring, and incident investigation.
Tenant Isolation
Superdegree is a multi-tenant platform, so preventing one organisation from accessing another organisation’s data is a core security requirement.
We use multiple layers of organisation-scoped access control, including database row-level security, server-side ownership checks, private object storage, and signed media access.
We also test tenant isolation across relevant database, application, privilege, and media-access paths to help identify cross-organisation access vulnerabilities.
Secure Development Lifecycle
Security is built into how we develop and operate Superdegree.
Code changes go through review and automated checks before deployment, and we maintain separate development, preview, and production environments.
We do not intentionally copy production Customer Content into development or test environments except where specifically required for authorised troubleshooting, security investigation, or testing with appropriate safeguards.
Secrets and credentials used by Superdegree are maintained using access-controlled environment or secrets-management mechanisms rather than being intentionally embedded in application source code.
Administrative access to production infrastructure is restricted to authorised personnel.
We maintain operational and security logging appropriate to the systems involved and monitor our systems for errors, failures, and anomalous activity.
Our incident response process is designed to identify, contain, investigate, and resolve security incidents.
Data Retention & Deletion
We retain Customer data only for as long as reasonably necessary to provide and support the Service, comply with Customer instructions, maintain security, or meet applicable legal obligations.
When Customer Content is deleted, it may remain recoverable for up to 30 days before permanent deletion from active systems.
Database backups are maintained on a rolling basis for up to 7 days and expire through their ordinary backup lifecycle.
Temporary media-processing artifacts are automatically deleted through lifecycle controls and may remain for up to 7 days, depending on the workflow.
Certain diagnostic information associated with failed or investigated Agent executions may be retained for up to 90 days, subject to limited exceptions for security investigations, support, legal obligations, or dispute resolution.
For complete details about retention and deletion, see our Privacy Policy.
Third-Party Infrastructure
Superdegree relies on specialised infrastructure and service providers to deliver different parts of the Service, including cloud hosting, databases, storage, AI processing, browser automation, analytics, payments, communications, and media processing.
We assess providers according to the role they perform and use contractual, technical, and organisational safeguards where appropriate.
Customer data may be processed by these providers only as necessary to provide and support the applicable functionality.
Our Privacy Policy provides further information about the providers we use and how Customer data is processed.
Business customers requiring contractual data-processing commitments can also request or review our Data Processing Addendum at [email protected].
Found something?
If you believe you've discovered a security vulnerability in Superdegree, please report it to us rather than attempting to exploit it or access other customers' data.
Please include enough information for us to reproduce and investigate the issue where possible.
We investigate security reports and work to address verified vulnerabilities according to their severity and potential impact.