Trust center
Security, compliance, and reliability, in the open.
Current posture, third-party attestation status, the full control catalog, the incident log, and the documents your reviewers need. No login, no form, no sales conversation.
Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.
What you can check
Security
27 controls
The control catalog, written for a reviewer rather than for a brochure, with framework references on every entry.
Compliance
7 programs
Attestation status per program, with the scope statement, the target date, and the honest status where no report exists yet.
Reliability
No incidents published
The incident log and the disclosure commitments it is measured against, published in advance rather than after the fact.
Privacy
7 sub-processors
Who processes what, where, under which transfer mechanism, with 30 days notice before a new one begins.
Transparency
10 open commitments
The published security roadmap, with a target quarter on every gap this page names.
Compliance programs
SOC 2 Type II
SecurityReadiness work is underway. Controls are designed and mapped, and the evidence pipeline collects them continuously. No report has been issued, so nothing on this page claims one has been.
ISO/IEC 27001
SecurityDeclared intent with a target quarter. The information security management system draws on the same control catalog as the SOC 2 work, so most of the mapping is shared.
HIPAA Security Rule
HealthcareArchitected to align with the HIPAA Security Rule. There is no certification body for HIPAA, so no certificate exists to show. What can be shown is the control mapping, which is published in full.
GDPR
PrivacyArchitected to align with GDPR principles, with a data processing agreement offered for download and standard contractual clauses attached as annexes.
All 7 programs, with scope statements
Documents
Privacy Policy
What personal data is collected, the lawful basis for processing it, how long it is kept, and how to exercise data subject rights.
Data Processing Agreement
Processor obligations under GDPR Article 28, with the EU standard contractual clauses and the UK addendum attached as annexes. Available to accept without a negotiation.
Terms of Service
The agreement governing use of the platform. Enterprise customers who need a counter-signed master services agreement can request one.
Sub-processor Register
The current register, with processing locations, transfer mechanisms, and the 30 day change notice commitment.
Reporting a vulnerability
Send findings to security@synapbridge.com. Good faith research within the published scope will not be pursued legally, and we will say so if a third party pursues action against a researcher acting within this policy.
A paid bounty programme is a published roadmap commitment and is not running yet. Claiming a bounty that does not pay costs more with researchers than it earns.