SynapBridge
Sign inGet started

Trust center

Certifications and compliance programs

Each program below carries the status it actually holds, the scope that was or will be assessed, and a target date where one is committed. Nothing is described as attested or certified without a published report behind it.

Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.

How to read this page.No program on this page currently holds a third-party attestation, and none of them says otherwise. The vocabulary is deliberate. Architected to align means the controls are designed and mapped against a framework with no independent artifact. Audit in progress means fieldwork or readiness work is underway. Attested and certified are reserved for programs with a published report or certificate, and the schema behind this page rejects a row that claims either without one.

All programs

7 programs across 5 framework families.
ProgramFamilyStatusPeriodIssuerNext target
SOC 2 Type IISecurityAudit in progressNot startedNot appointed31 Mar 2027
ISO/IEC 27001SecurityPlannedNot startedNot appointed31 Dec 2027
HIPAA Security RuleHealthcareArchitected to alignNot startedNot appointedNot scheduled
GDPRPrivacyArchitected to alignNot startedNot appointedNot scheduled
PCI DSSPaymentsArchitected to alignNot startedNot appointedNot scheduled
NIST AI Risk Management FrameworkAIArchitected to alignNot startedNot appointedNot scheduled
EU AI ActAIIn scopeNot startedNot appointed30 Jun 2027

Program detail

SOC 2 Type II

Security
Audit in progress
Scope

Planned scope covers the SynapBridge control plane, the tenant data plane, and the provider gateway, against the Security, Availability, and Confidentiality trust services criteria. Scope is provisional until the engagement letter is signed.

Readiness work is underway. Controls are designed and mapped, and the evidence pipeline collects them continuously. No report has been issued, so nothing on this page claims one has been.

The control set is mapped in the practices catalog and each control carries its framework reference. Two criteria are recorded as partial today: risk assessment cadence, where the initial threat model is complete but the quarterly review is not yet operational, and availability, where recovery targets are documented but disaster recovery testing has not been exercised. Both are published as roadmap commitments with a target quarter rather than being omitted.

An auditor has not been selected. Until one is, this page cannot show an issuer, and the status stays at audit in progress.

Audit periodNot started
Valid untilNot applicable
Next target31 Mar 2027
Independent bodyNot appointed
ArtifactNo report issued

ISO/IEC 27001

Security
Planned
Scope

Planned scope is the full platform, including the control plane, data plane, and the supporting corporate systems that hold customer data.

Declared intent with a target quarter. The information security management system draws on the same control catalog as the SOC 2 work, so most of the mapping is shared.

ISO/IEC 27001 follows the SOC 2 engagement rather than running alongside it. Running both at once would mean two evidence collection cycles against a control set that is still stabilising, and a certificate obtained under that pressure would say less than the date on it suggests.

Audit periodNot started
Valid untilNot applicable
Next target31 Dec 2027
Independent bodyNot appointed
ArtifactNo report issued

HIPAA Security Rule

Healthcare
Architected to align
Scope

Technical, administrative, and physical safeguards under 45 CFR 164.308, 164.310, and 164.312, as they apply to protected health information processed through the platform.

Architected to align with the HIPAA Security Rule. There is no certification body for HIPAA, so no certificate exists to show. What can be shown is the control mapping, which is published in full.

HIPAA has no accrediting body and no certificate. Any vendor that advertises a HIPAA certification is describing something that does not exist. What is verifiable is the safeguard mapping and a signed business associate agreement, both of which are available.

Two safeguards are recorded as partial: contingency planning, where backups are in place but disaster recovery testing is pending, and the formal policy catalog, where the documents exist but are not yet organised as a single reviewed catalog. Facility access controls are marked not applicable and inherited from the AWS shared responsibility model.

Audit periodNot started
Valid untilNot applicable
Next targetNot scheduled
Independent bodyNot appointed
ArtifactNo report issued

GDPR

Privacy
Architected to align
Scope

Articles 5 and 32 principles, data subject rights under Articles 15 to 22, and processor obligations under Article 28, covering personal data processed on behalf of controllers.

Architected to align with GDPR principles, with a data processing agreement offered for download and standard contractual clauses attached as annexes.

Two rights are recorded as partial. The right to erasure is honoured through workspace deletion, but the per-user deletion flow does not yet carry an explicit verification step. Data portability is available as a workspace export on the Business tier and is not yet exposed as a subject access request endpoint. Both are roadmap items with target quarters.

Records of processing activities, transfer impact assessments, and breach runbooks are maintained internally and are available under the document request flow.

Audit periodNot started
Valid untilNot applicable
Next targetNot scheduled
Independent bodyNot appointed
ArtifactNo report issued

PCI DSS

Payments
Architected to align
Scope

SAQ-A scope only. Cardholder data never reaches SynapBridge infrastructure: the payment surface is hosted by Stripe and card details are entered directly into Stripe-hosted fields. SynapBridge stores a payment method token and nothing else.

SAQ-A scope, because card data does not touch our systems. The scope statement says so in the first sentence rather than in a footnote, since this is the field vendors most often overstate.

The honest posture here is narrow and worth stating precisely. Stripe hosts the payment form. Card numbers, expiry dates, and security codes are submitted directly to Stripe and are never transmitted through, processed by, or stored on SynapBridge infrastructure. That places the integration in SAQ-A scope.

A vendor in SAQ-A scope who describes themselves as PCI compliant without naming the scope is inviting a reader to assume a much larger assessment took place. This page names it.

Audit periodNot started
Valid untilNot applicable
Next targetNot scheduled
Independent bodyNot appointed
ArtifactNo report issued

NIST AI Risk Management Framework

AI
Architected to align
Scope

Govern, Map, Measure, and Manage functions as applied to the governance layer, the provider gateway, and the model routing surface.

Architected to align with the NIST AI Risk Management Framework. The framework is voluntary and carries no certificate; the mapping is published in the practices catalog.

Supply chain risk management is recorded as partial: dependency review runs on every pull request, but a formal software bill of materials is pending. Contingency planning is partial for the same reason it is partial under SOC 2, and the two share a single roadmap item rather than being tracked twice.

Audit periodNot started
Valid untilNot applicable
Next targetNot scheduled
Independent bodyNot appointed
ArtifactNo report issued

EU AI Act

AI
In scope
Scope

Provider and deployer obligations for general purpose AI systems, transparency obligations, and the record-keeping requirements that apply to the governance layer.

Controls are designed and mapped against the applicable obligations. Conformity assessment routes are still settling across member states, so no date is committed beyond the readiness target.

Bias evaluation tooling is pending and is published as a roadmap item. The audit trail, model registry, and use case register that the record-keeping obligations depend on are in place today and are described in the practices catalog.

Audit periodNot started
Valid untilNot applicable
Next target30 Jun 2027
Independent bodyNot appointed
ArtifactNo report issued

Where the gaps are

Every program above that is not attested has a corresponding entry on the roadmap with a target quarter. The controls behind them, including the ones recorded as partial, are published in full on the security practices page rather than summarised into a score.

Security contactsecurity@synapbridge.com
Privacy contactprivacy@synapbridge.com
Legal and procurementlegal@synapbridge.com