Last Modified: August 4, 2026
Summary
Sundial is a Chrome extension that enhances scheduling efficiency in Google Calendar. See how it works here, or install it from the Chrome Web Store here.
This page outlines Sundial’s security and compliance approach for enterprise review. For inquiries, contact support@trysundial.ai.
- Chrome Extension Security: Built on Chrome Extension Manifest V3. Content scripts run only on https://calendar.google.com/*, host permissions are limited to https://trysundial.ai/*, and Sundial does not request broad <all_urls> host permissions.
- Least-Privilege Access: Only the minimum Chrome permissions and Google OAuth scopes required for each feature are requested.
- SOC 2 Type II: Completed November 2025; Current audit underway. Live controls status.
- Independent Security Testing: Regular third-party penetration testing. Latest summary available here.
- Enterprise Integration: Supports SAML 2.0 SSO.
- Data Minimization: Google Calendar data is accessed only when users explicitly invoke a feature. Google Calendar event content is not persistently retained. Poll data (title, proposed times, guest emails, votes, optional notes) is encrypted at rest and permanently deleted 90 days after the poll is created.
- Data Control: Users and enterprises can delete data anytime via dashboard or by request.
- AI: No storage or training. User-provided scheduling text and images are processed ephemerally. Customer data is not used to train AI models, and subprocessors are contractually prohibited from using customer data for model training.
Table of Contents
Access Required
To view the full security review, email support@trysundial.ai asking for access.