Trust Center
The controls protecting your data, your customers, and your operations.
Everything your security and procurement teams need, in one place.
Our security commitments
What every Syntic customer gets, on every plan.
Every Syntic plan, every customer, every deployment.
Your data stays yours
Customer data, including chat content, voice transcripts, uploaded documents, knowledge sources, and Agent Execution traces, is never used to train shared models. Not as a default setting, not as a clause buried in the terms. Contractually, on every plan.
Encryption everywhere
Data encrypted in transit using TLS 1.3. Data at rest encrypted with AES-256. Encryption keys managed by Syntic on standard plans; customer-managed keys (BYOK) available on Enterprise.
Isolated runtimes
Every Project gets a dedicated, isolated runtime. Memory, knowledge sources, credentials, and Agent Executions stay inside the Project's boundary. No cross-Project data access by default.
Audit trail on everything
Every Agent Execution, Approval, version change, human takeover, and API call logged with timestamp and actor. Exportable on Team plans and above.
Role-based access control
Owner, Admin, Manager, Reviewer, and Viewer roles. SSO and SCIM on Team and above. Permission scoping at the Project, Employee, and channel level.
Vulnerability disclosure
Responsible disclosure program at security.syntic.ai. We respond to verified reports within 48 hours and publish CVE-style advisories for resolved issues.
Compliance and certifications
Where we are. Where we're going. Honest about both.
In production
GDPR (EU) and UK GDPR
Data Processing Agreement available on all paid plans. EU and UK data residency on Business and Enterprise. Standard Contractual Clauses for cross-border transfers. Data subject access request handling within statutory timelines.
CCPA (California) and equivalent US state privacy laws
Privacy policy disclosures, opt-out flows, and data subject rights handling per CCPA, CPRA, CDPA Virginia, CPA Colorado, and equivalent emerging state frameworks.
HIPAA (US healthcare)
Business Associate Agreement available on Business and Enterprise plans. PHI handled in dedicated, isolated runtimes. Audit logging meets HIPAA Security Rule requirements.
PIPEDA, DPDP, Privacy Act, POPIA, LGPD
Equivalent privacy framework support per jurisdiction for Canada, India, Australia, South Africa, and Brazil. Regional data residency available.
In progress
SOC 2 Type II
Audit in progress, target completion Q4 2026. Type I report available under NDA. We've engaged a Big Four auditor; controls are designed to AICPA TSC criteria covering Security, Availability, Confidentiality, and Privacy.
ISO 27001
ISMS implementation in progress. Target certification Q1 2027.
HITRUST CSF
Roadmap defined for healthcare-focused engagements. Target self-assessment in Q1 2027; CSF v11 certification on the longer roadmap.
PCI DSS
Scoped for payment processing workflows. Compliance assessment in progress, expected completion alongside SOC 2.
Roadmap
FedRAMP Moderate
Authorization roadmap defined for US federal government work. Currently engaged with a 3PAO. Target ATO timeline driven by first federal customer engagement.
DoD Impact Levels IL2, IL4, IL5
Roadmap defined alongside FedRAMP authorization.
C5, SecNumCloud, G-Cloud
European public sector framework alignment for Germany, France, and the UK, scoped for 2027 customer engagements.
IRAP, ISMAP, MTCS, K-ISMS
APAC public sector framework alignment for Australia, Japan, Singapore, and Korea, scoped for 2027 customer engagements.
Data handling
Full data lifecycle documentation — what we collect, how we use it, retention schedules, and deletion — is in our Privacy Policy and Data Processing Agreement, available on all paid plans.
Infrastructure security
The boundary your work runs inside.
Cloud infrastructure
Multi-region deployment on tier-1 cloud providers AWS, GCP, and Azure with redundancy across availability zones. Enterprise customers can request dedicated regional deployment or sovereign cloud options.
Network security
All traffic encrypted in transit. VPC isolation. Private network connectivity including PrivateLink, Private Service Connect, and Private Endpoints on Business and Enterprise. Web Application Firewall and DDoS protection at the edge.
Access controls
Production access restricted to a small number of personnel with documented business need. Just-in-time access for sensitive operations. Multi-factor authentication required for all employee access. Hardware security keys required for production system access.
Monitoring and detection
24/7 security monitoring with SIEM. Endpoint detection and response on all corporate and production endpoints. Continuous vulnerability scanning on infrastructure and weekly on dependencies. Annual penetration testing by independent third parties.
Incident response
Documented runbooks. Customer notification within 72 hours for incidents involving customer data; faster for confirmed breaches. Post-incident reviews published at syntic.ai/transparency.
Business continuity
Multi-region active-active for critical services. Documented disaster recovery procedures with quarterly testing. RTO and RPO commitments available on Business and Enterprise plans.
AI-specific safety and controls
What we built specifically for the risks of AI workforce platforms.
Model isolation
Customer data is never used to train shared models. Custom model engagements for Enterprise train only on the customer's data, deployed only inside the customer's environment. Your data trains models that belong to you — or it doesn't get used for training at all.
Output safety
Built-in content filtering for harmful, illegal, and policy-violating outputs. Configurable content policies per Employee and per deployment. Compliance-aware language enforcement for regulated domains — FDCPA, HIPAA, GDPR, FERPA, and others — built into the Employee at hire, not configured as an afterthought.
Approval gates
Configurable Approval requirements on irreversible actions like payments, contracts, hires, and escalations. Human-in-the-loop by default on actions above customer-defined thresholds.
Human takeover
One-click human takeover on every voice call and every text conversation. Customers control how and when AI Employees yield to humans.
Voice safeguards
Optional AI disclosure on inbound and outbound voice calls per jurisdictional requirements. TCPA pacing and consent enforcement on US outbound. DNC list enforcement. Recording disclosure where required.
Versioning and rollback
Every AI Employee is versioned, with one-click rollback to any previous version. Every Agent Execution attributed to the version that ran it. Audit trail of who changed what when.
Scoped credentials
Every Employee has a scoped credential set. Default-deny on file system access, network egress, and third-party tool access. Customers explicitly grant each capability per Employee.
Subprocessors
The third parties we use to deliver Syntic.
Third-party vendors used to deliver Syntic. Material changes notified 30 days in advance for Business and Enterprise customers. Full current list at trust.syntic.ai/subprocessors.
For customers and procurement teams
What we provide to make your diligence easier.
Standard documentation
- Security and compliance overview downloadable as PDF
- Data Processing Agreement on all paid plans
- Business Associate Agreement on Business and Enterprise
- Standard Contractual Clauses where required
- Current subprocessor list with notification rights
- Versioned privacy policy and terms of service with change history
Under NDA
- SOC 2 Type I report
- Most recent annual penetration testing report
- Vulnerability disclosure history
- Incident response procedures
- Business continuity and disaster recovery plan
- Architecture and data flow diagrams
- Pre-filled security questionnaires SIG, SIG Lite, CAIQ
On Business and Enterprise
- Live security calls with our team
- Custom security questionnaire responses including SOC 2 SIG, HECVAT, and custom RFPs
- Validation evidence packages
- Customer-specific compliance scoping for HIPAA, FDCPA, GDPR, and industry-specific frameworks
Responsible disclosure
Security researchers: full responsible disclosure scope, process, and reporting at security.syntic.ai.
Trust and AI
How we think about responsible AI at the scale of an AI workforce platform.
Customer data is sovereign. It is never used to train shared models — not as a default setting, not buried in a terms update. Customers own their data, their Employees, their custom models, and their work products. We are vendors. Not data brokers. Not advertising platforms. Not a company whose business model depends on what you put into the product.
Humans stay in the loop. Approvals on irreversible actions, takeover on every voice and text channel, and audit logs on everything. AI Employees augment human teams; they don't replace human judgment on the decisions that matter.
Compliance is built in, not bolted on. Regulated workflows in collections, healthcare, financial services, and public sector ship with their compliance frameworks built into the Employee design. Audit trails, approval gates, and consent flows are platform primitives.
We're honest about what we don't have yet. SOC 2 Type II is in progress — we say "in progress," not "certified." FedRAMP is on the roadmap — we say "roadmap," not "authorized." We will update this page to say "certified" the day after the certificate is issued. The roadmap is public and on this page. The customer engagements that fund it are how we get there — and we will not claim to have arrived before we have.
The threat model includes us. We do not assume our own people are trustworthy by default. Internal access to production systems is limited to a small number of personnel with documented business need, requires hardware security keys and just-in-time approval, and is logged in full. Personnel are vetted. Access is reviewed regularly and revoked immediately on role change or departure. We designed the controls assuming that a Syntic employee could become a threat vector — because that assumption is always correct and ignoring it is how breaches happen.
Status and history
Current service health and incident history: status.syntic.ai
Get in touch
Reach the team that owns trust at Syntic.
Security and compliance — security@syntic.ai. For procurement diligence, compliance scoping, security questionnaires, and BAA or DPA requests.
Privacy and data rights — privacy@syntic.ai. For data subject access requests, deletion requests, and privacy framework questions. DSAR portal at trust.syntic.ai/dsar.
Vulnerability reports — security@syntic.ai. PGP key at trust.syntic.ai/pgp. We acknowledge within 24 hours and respond to verified findings within 48.
Service status and incidents — status.syntic.ai. Real-time health and full incident history.
Security pack request — the button below. Standard documentation package delivered within one business day for most requests.