Trust center
Certifications and compliance programs
Each program below carries the status it actually holds, the scope that was or will be assessed, and a target date where one is committed. Nothing is described as attested or certified without a published report behind it.
Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.
All programs
| Program | Family | Status | Period | Issuer | Next target |
|---|---|---|---|---|---|
| SOC 2 Type II | Security | Audit in progress | Not started | Not appointed | 31 Mar 2027 |
| ISO/IEC 27001 | Security | Planned | Not started | Not appointed | 31 Dec 2027 |
| HIPAA Security Rule | Healthcare | Architected to align | Not started | Not appointed | Not scheduled |
| GDPR | Privacy | Architected to align | Not started | Not appointed | Not scheduled |
| PCI DSS | Payments | Architected to align | Not started | Not appointed | Not scheduled |
| NIST AI Risk Management Framework | AI | Architected to align | Not started | Not appointed | Not scheduled |
| EU AI Act | AI | In scope | Not started | Not appointed | 30 Jun 2027 |
Program detail
SOC 2 Type II
SecurityPlanned scope covers the SynapBridge control plane, the tenant data plane, and the provider gateway, against the Security, Availability, and Confidentiality trust services criteria. Scope is provisional until the engagement letter is signed.
Readiness work is underway. Controls are designed and mapped, and the evidence pipeline collects them continuously. No report has been issued, so nothing on this page claims one has been.
The control set is mapped in the practices catalog and each control carries its framework reference. Two criteria are recorded as partial today: risk assessment cadence, where the initial threat model is complete but the quarterly review is not yet operational, and availability, where recovery targets are documented but disaster recovery testing has not been exercised. Both are published as roadmap commitments with a target quarter rather than being omitted.
An auditor has not been selected. Until one is, this page cannot show an issuer, and the status stays at audit in progress.
ISO/IEC 27001
SecurityPlanned scope is the full platform, including the control plane, data plane, and the supporting corporate systems that hold customer data.
Declared intent with a target quarter. The information security management system draws on the same control catalog as the SOC 2 work, so most of the mapping is shared.
ISO/IEC 27001 follows the SOC 2 engagement rather than running alongside it. Running both at once would mean two evidence collection cycles against a control set that is still stabilising, and a certificate obtained under that pressure would say less than the date on it suggests.
HIPAA Security Rule
HealthcareTechnical, administrative, and physical safeguards under 45 CFR 164.308, 164.310, and 164.312, as they apply to protected health information processed through the platform.
Architected to align with the HIPAA Security Rule. There is no certification body for HIPAA, so no certificate exists to show. What can be shown is the control mapping, which is published in full.
HIPAA has no accrediting body and no certificate. Any vendor that advertises a HIPAA certification is describing something that does not exist. What is verifiable is the safeguard mapping and a signed business associate agreement, both of which are available.
Two safeguards are recorded as partial: contingency planning, where backups are in place but disaster recovery testing is pending, and the formal policy catalog, where the documents exist but are not yet organised as a single reviewed catalog. Facility access controls are marked not applicable and inherited from the AWS shared responsibility model.
GDPR
PrivacyArticles 5 and 32 principles, data subject rights under Articles 15 to 22, and processor obligations under Article 28, covering personal data processed on behalf of controllers.
Architected to align with GDPR principles, with a data processing agreement offered for download and standard contractual clauses attached as annexes.
Two rights are recorded as partial. The right to erasure is honoured through workspace deletion, but the per-user deletion flow does not yet carry an explicit verification step. Data portability is available as a workspace export on the Business tier and is not yet exposed as a subject access request endpoint. Both are roadmap items with target quarters.
Records of processing activities, transfer impact assessments, and breach runbooks are maintained internally and are available under the document request flow.
PCI DSS
PaymentsSAQ-A scope only. Cardholder data never reaches SynapBridge infrastructure: the payment surface is hosted by Stripe and card details are entered directly into Stripe-hosted fields. SynapBridge stores a payment method token and nothing else.
SAQ-A scope, because card data does not touch our systems. The scope statement says so in the first sentence rather than in a footnote, since this is the field vendors most often overstate.
The honest posture here is narrow and worth stating precisely. Stripe hosts the payment form. Card numbers, expiry dates, and security codes are submitted directly to Stripe and are never transmitted through, processed by, or stored on SynapBridge infrastructure. That places the integration in SAQ-A scope.
A vendor in SAQ-A scope who describes themselves as PCI compliant without naming the scope is inviting a reader to assume a much larger assessment took place. This page names it.
NIST AI Risk Management Framework
AIGovern, Map, Measure, and Manage functions as applied to the governance layer, the provider gateway, and the model routing surface.
Architected to align with the NIST AI Risk Management Framework. The framework is voluntary and carries no certificate; the mapping is published in the practices catalog.
Supply chain risk management is recorded as partial: dependency review runs on every pull request, but a formal software bill of materials is pending. Contingency planning is partial for the same reason it is partial under SOC 2, and the two share a single roadmap item rather than being tracked twice.
EU AI Act
AIProvider and deployer obligations for general purpose AI systems, transparency obligations, and the record-keeping requirements that apply to the governance layer.
Controls are designed and mapped against the applicable obligations. Conformity assessment routes are still settling across member states, so no date is committed beyond the readiness target.
Bias evaluation tooling is pending and is published as a roadmap item. The audit trail, model registry, and use case register that the record-keeping obligations depend on are in place today and are described in the practices catalog.
Where the gaps are
Every program above that is not attested has a corresponding entry on the roadmap with a target quarter. The controls behind them, including the ones recorded as partial, are published in full on the security practices page rather than summarised into a score.