PioneerAILog in or Sign up
PioneerAI
Log in or Sign up

Technical & Organizational Measures (TOMs)

Last updated: August 25, 2026


Mycorrxyz Inc. dba Pioneer implements the following measures. Measures marked "(inherited)" are provided by Pioneer's audited infrastructure providers. Pioneer operates no physical servers.

1. Infrastructure and hosting

  • The Service runs entirely on managed cloud infrastructure: Supabase (database, authentication, file storage) and Vercel (application hosting and delivery), each SOC 2 Type 2 certified. These certifications belong to the providers and cover their platforms; Pioneer does not claim its own SOC 2 certification. Provider audit report summaries are available on request.
  • Background processing runs on Inngest (US). All AI inference is performed by OpenAI and Anthropic (both US) under API terms that prohibit training on submitted data.
  • Data is processed primarily in the United States. The single exception is an EU-based email verification service that receives bare email addresses only; the current list of all subprocessors, their locations, and their purposes is published in the Subprocessor List.

2. Encryption

  • In transit: TLS 1.2 or higher for all connections between users, the application, and all subprocessors.
  • At rest: database and file storage encrypted at rest by infrastructure providers (AES-256) (inherited).
  • Secrets and credentials are managed through environment configuration, never stored in source code.

3. Identity and access control

  • No password storage: users authenticate via Google OAuth or emailed magic links. Pioneer never holds user passwords.
  • Sessions use short-lived tokens in httpOnly cookies (15-minute application tokens with managed refresh).
  • Customer data is logically separated by organization; application authorization restricts access to members of the owning organization, enforced at the database layer.
  • Internal access to production systems is restricted to authorized personnel on a least-privilege basis and used only to operate and support the Service.
  • All database reads and writes are audit-logged (pgaudit), providing a per-action trail for security investigations.

4. Data lifecycle

  • Deletion: customers can delete their account and organization in-product with immediate effect. Pioneer does not retain copies of deleted customer data except short-lived infrastructure backups that roll off automatically and records required for billing, legal, or security purposes.
  • Post-termination: Customer Personal Data is deleted within the period stated in DPA Section 11.
  • No training: no customer data enters any model training dataset or model weights, directly or indirectly; AI providers are contractually barred from training on API data.
  • Minimization: data sent to AI providers and research services is limited to what the requested task requires.

5. Availability and resilience

  • Managed database with automated backups and provider-managed failover (inherited).
  • Serverless application architecture with global edge delivery (inherited).
  • Background jobs use orchestration with retries and dead-letter handling.
  • Usage and billing operations are recorded in a double-entry ledger providing a financial audit trail.

6. Monitoring and incident management

  • Continuous error monitoring (Sentry) and performance telemetry alert engineering leadership to failures.
  • Security Incidents affecting Customer Personal Data are notified to affected customers without undue delay, and in any event within three business days of Pioneer becoming aware (DPA Section 7), with remediation updates through resolution.
  • Vulnerability reports are accepted and acknowledged per the Vulnerability Disclosure Policy.

7. Secure development

  • All changes are made through pull-request review with automated builds and isolated preview environments; no direct changes to production.
  • Dependency versions are actively managed with security overrides applied at the package level.
  • Production database access for development purposes is prohibited; schema changes ship as reviewed migrations.

8. Subprocessor governance

  • All subprocessors are published with purpose, data categories, and location in the Subprocessor List.
  • New or replacement subprocessors are added to the published list before use; the list is the notice mechanism (DPA Section 5).
  • Vendors are assessed for certifications and API data-use terms before adoption.

9. Organizational measures

  • Security responsibility is held directly by executive leadership.
  • Personnel and contractors with any data access are bound by confidentiality obligations.
  • These measures are reviewed at least annually and upon material changes to the architecture, and this document is updated accordingly.

Questions or security review requests: privacy@pioneerclimate.com. Pioneer answers written security questionnaires and provides provider audit summaries on request (DPA Section 10).

PioneerAI © 2026ContactTermsPrivacyLegal