Security Overview
Last updated: September 27, 2026
This page describes only controls that exist in the product today.
Certifications. Synseus does not hold a SOC 2 report or any other third-party certification, and no audit is under way.
What is in place
| Area | What is in place |
|---|---|
| Hosting | Vercel, United States (Washington, D.C. region); HTTPS for all traffic |
| Database | Supabase-managed PostgreSQL, United States (Oregon region) |
| Passwords | Stored only as bcrypt hashes (cost 12) |
| Integration credentials | Encrypted with AES-256-GCM through a single code path; if the key is missing or invalid, nothing is stored. No integrations are offered today, and none are stored. |
| Client data | Not collected through connections: CRM and calendar connections are not offered |
| Access control | Role-based access for multi-seat firms; administrator actions logged with IP address and browser details |
| AI | One provider (Anthropic) through a single code path; every request carries an instruction never to invent a figure |
| Fonts | Served from synseus.com; the site makes no font requests to Google |
| Analytics | Google Tag Manager / Analytics, loaded only after a visitor allows analytics cookies |
| Payments | Stripe; Synseus stores no card numbers or card details |
| Error reporting | Sentry is installed but not switched on; no error data leaves the product |
| Breach response | Customer notification within 72 hours, as set out on our compliance page |
| Deletion and export | Self-service in Settings → Privacy & Data: export is prepared at once; deletion is confirmed by email and completed 30 days after confirmation by a daily scheduled job |
Not in place, and not claimed
Penetration testing; a retention schedule beyond deletion on request; removal of personal information before AI requests (no client records are held through connections); a public health endpoint for monitoring; error reporting.
Contact
Security questions, vulnerability reports and compliance questions: [email protected]. Messages to this address reach our team directly and are tracked as support tickets. We respond to compliance questions within one business day and will complete a reasonable vendor risk assessment on request.