Syntic

Trust Center

The controls protecting your data, your customers, and your operations.

Everything your security and procurement teams need, in one place.

Our security commitments

What every Syntic customer gets, on every plan.

Every Syntic plan, every customer, every deployment.

Your data stays yours

Customer data, including chat content, voice transcripts, uploaded documents, knowledge sources, and Agent Execution traces, is never used to train shared models. Not as a default setting, not as a clause buried in the terms. Contractually, on every plan.

Encryption everywhere

Data encrypted in transit using TLS 1.3. Data at rest encrypted with AES-256. Encryption keys managed by Syntic on standard plans; customer-managed keys (BYOK) available on Enterprise.

Isolated runtimes

Every Project gets a dedicated, isolated runtime. Memory, knowledge sources, credentials, and Agent Executions stay inside the Project's boundary. No cross-Project data access by default.

Audit trail on everything

Every Agent Execution, Approval, version change, human takeover, and API call logged with timestamp and actor. Exportable on Team plans and above.

Role-based access control

Owner, Admin, Manager, Reviewer, and Viewer roles. SSO and SCIM on Team and above. Permission scoping at the Project, Employee, and channel level.

Vulnerability disclosure

Responsible disclosure program at security.syntic.ai. We respond to verified reports within 48 hours and publish CVE-style advisories for resolved issues.

Compliance and certifications

Where we are. Where we're going. Honest about both.

In production

GDPR (EU) and UK GDPR

Data Processing Agreement available on all paid plans. EU and UK data residency on Business and Enterprise. Standard Contractual Clauses for cross-border transfers. Data subject access request handling within statutory timelines.

CCPA (California) and equivalent US state privacy laws

Privacy policy disclosures, opt-out flows, and data subject rights handling per CCPA, CPRA, CDPA Virginia, CPA Colorado, and equivalent emerging state frameworks.

HIPAA (US healthcare)

Business Associate Agreement available on Business and Enterprise plans. PHI handled in dedicated, isolated runtimes. Audit logging meets HIPAA Security Rule requirements.

PIPEDA, DPDP, Privacy Act, POPIA, LGPD

Equivalent privacy framework support per jurisdiction for Canada, India, Australia, South Africa, and Brazil. Regional data residency available.

In progress

SOC 2 Type II

Audit in progress, target completion Q4 2026. Type I report available under NDA. We've engaged a Big Four auditor; controls are designed to AICPA TSC criteria covering Security, Availability, Confidentiality, and Privacy.

ISO 27001

ISMS implementation in progress. Target certification Q1 2027.

HITRUST CSF

Roadmap defined for healthcare-focused engagements. Target self-assessment in Q1 2027; CSF v11 certification on the longer roadmap.

PCI DSS

Scoped for payment processing workflows. Compliance assessment in progress, expected completion alongside SOC 2.

Roadmap

FedRAMP Moderate

Authorization roadmap defined for US federal government work. Currently engaged with a 3PAO. Target ATO timeline driven by first federal customer engagement.

DoD Impact Levels IL2, IL4, IL5

Roadmap defined alongside FedRAMP authorization.

C5, SecNumCloud, G-Cloud

European public sector framework alignment for Germany, France, and the UK, scoped for 2027 customer engagements.

IRAP, ISMAP, MTCS, K-ISMS

APAC public sector framework alignment for Australia, Japan, Singapore, and Korea, scoped for 2027 customer engagements.

Data handling

Full data lifecycle documentation — what we collect, how we use it, retention schedules, and deletion — is in our Privacy Policy and Data Processing Agreement, available on all paid plans.

Infrastructure security

The boundary your work runs inside.

Cloud infrastructure

Multi-region deployment on tier-1 cloud providers AWS, GCP, and Azure with redundancy across availability zones. Enterprise customers can request dedicated regional deployment or sovereign cloud options.

Network security

All traffic encrypted in transit. VPC isolation. Private network connectivity including PrivateLink, Private Service Connect, and Private Endpoints on Business and Enterprise. Web Application Firewall and DDoS protection at the edge.

Access controls

Production access restricted to a small number of personnel with documented business need. Just-in-time access for sensitive operations. Multi-factor authentication required for all employee access. Hardware security keys required for production system access.

Monitoring and detection

24/7 security monitoring with SIEM. Endpoint detection and response on all corporate and production endpoints. Continuous vulnerability scanning on infrastructure and weekly on dependencies. Annual penetration testing by independent third parties.

Incident response

Documented runbooks. Customer notification within 72 hours for incidents involving customer data; faster for confirmed breaches. Post-incident reviews published at syntic.ai/transparency.

Business continuity

Multi-region active-active for critical services. Documented disaster recovery procedures with quarterly testing. RTO and RPO commitments available on Business and Enterprise plans.

AI-specific safety and controls

What we built specifically for the risks of AI workforce platforms.

Model isolation

Customer data is never used to train shared models. Custom model engagements for Enterprise train only on the customer's data, deployed only inside the customer's environment. Your data trains models that belong to you — or it doesn't get used for training at all.

Output safety

Built-in content filtering for harmful, illegal, and policy-violating outputs. Configurable content policies per Employee and per deployment. Compliance-aware language enforcement for regulated domains — FDCPA, HIPAA, GDPR, FERPA, and others — built into the Employee at hire, not configured as an afterthought.

Approval gates

Configurable Approval requirements on irreversible actions like payments, contracts, hires, and escalations. Human-in-the-loop by default on actions above customer-defined thresholds.

Human takeover

One-click human takeover on every voice call and every text conversation. Customers control how and when AI Employees yield to humans.

Voice safeguards

Optional AI disclosure on inbound and outbound voice calls per jurisdictional requirements. TCPA pacing and consent enforcement on US outbound. DNC list enforcement. Recording disclosure where required.

Versioning and rollback

Every AI Employee is versioned, with one-click rollback to any previous version. Every Agent Execution attributed to the version that ran it. Audit trail of who changed what when.

Scoped credentials

Every Employee has a scoped credential set. Default-deny on file system access, network egress, and third-party tool access. Customers explicitly grant each capability per Employee.

Subprocessors

The third parties we use to deliver Syntic.

Third-party vendors used to deliver Syntic. Material changes notified 30 days in advance for Business and Enterprise customers. Full current list at trust.syntic.ai/subprocessors.

For customers and procurement teams

What we provide to make your diligence easier.

Standard documentation

  • Security and compliance overview downloadable as PDF
  • Data Processing Agreement on all paid plans
  • Business Associate Agreement on Business and Enterprise
  • Standard Contractual Clauses where required
  • Current subprocessor list with notification rights
  • Versioned privacy policy and terms of service with change history

Under NDA

  • SOC 2 Type I report
  • Most recent annual penetration testing report
  • Vulnerability disclosure history
  • Incident response procedures
  • Business continuity and disaster recovery plan
  • Architecture and data flow diagrams
  • Pre-filled security questionnaires SIG, SIG Lite, CAIQ

On Business and Enterprise

  • Live security calls with our team
  • Custom security questionnaire responses including SOC 2 SIG, HECVAT, and custom RFPs
  • Validation evidence packages
  • Customer-specific compliance scoping for HIPAA, FDCPA, GDPR, and industry-specific frameworks

Responsible disclosure

Security researchers: full responsible disclosure scope, process, and reporting at security.syntic.ai.

Trust and AI

How we think about responsible AI at the scale of an AI workforce platform.

  • Customer data is sovereign. It is never used to train shared models — not as a default setting, not buried in a terms update. Customers own their data, their Employees, their custom models, and their work products. We are vendors. Not data brokers. Not advertising platforms. Not a company whose business model depends on what you put into the product.

  • Humans stay in the loop. Approvals on irreversible actions, takeover on every voice and text channel, and audit logs on everything. AI Employees augment human teams; they don't replace human judgment on the decisions that matter.

  • Compliance is built in, not bolted on. Regulated workflows in collections, healthcare, financial services, and public sector ship with their compliance frameworks built into the Employee design. Audit trails, approval gates, and consent flows are platform primitives.

  • We're honest about what we don't have yet. SOC 2 Type II is in progress — we say "in progress," not "certified." FedRAMP is on the roadmap — we say "roadmap," not "authorized." We will update this page to say "certified" the day after the certificate is issued. The roadmap is public and on this page. The customer engagements that fund it are how we get there — and we will not claim to have arrived before we have.

  • The threat model includes us. We do not assume our own people are trustworthy by default. Internal access to production systems is limited to a small number of personnel with documented business need, requires hardware security keys and just-in-time approval, and is logged in full. Personnel are vetted. Access is reviewed regularly and revoked immediately on role change or departure. We designed the controls assuming that a Syntic employee could become a threat vector — because that assumption is always correct and ignoring it is how breaches happen.

Status and history

Current service health and incident history: status.syntic.ai

Get in touch

Reach the team that owns trust at Syntic.

Security and compliance — security@syntic.ai. For procurement diligence, compliance scoping, security questionnaires, and BAA or DPA requests.

Privacy and data rights — privacy@syntic.ai. For data subject access requests, deletion requests, and privacy framework questions. DSAR portal at trust.syntic.ai/dsar.

Vulnerability reports — security@syntic.ai. PGP key at trust.syntic.ai/pgp. We acknowledge within 24 hours and respond to verified findings within 48.

Service status and incidents — status.syntic.ai. Real-time health and full incident history.

Security pack request — the button below. Standard documentation package delivered within one business day for most requests.