SynapBridge
Sign inGet started

Trust center

Frequently asked questions

The questions that show up in vendor security questionnaires, answered in full. Each answer has its own link, so a response can cite the source rather than paraphrase it.

Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.

Compliance (3)Contracts (1)Privacy (4)Reliability and incidents (2)Security (4)

Compliance

Do you have a SOC 2 report?

Not yet. Readiness work is underway with a target of the first quarter of 2027, and the status is published on the certifications page as audit in progress. When a report is issued, the certifications page will show the issuing firm, the observation period, the scope statement, and a way to request the report under NDA. Until then this page will not use the word attested, and the schema behind it will not permit that word without a linked report.

Why do some of your controls say partial?

Because they are. A control marked partial has something real behind it and something still missing, and both are described in the control's own entry. Marking those controls as implemented would make the catalog easier to read and would make it wrong. Each partial control that has a path to completion appears on the roadmap with a target quarter, so the gap comes with a date rather than an assurance.

Will you sign a BAA?

BAA available on request, subject to counsel review, on plans where protected health information is in scope. There is no HIPAA certification body, so no certificate exists for any vendor to show; what can be shown is the safeguard mapping, which is published in full on the practices page, including the two safeguards currently recorded as partial.

Contracts

Can I get a DPA without a negotiation?

Yes. The data processing agreement is published with the EU standard contractual clauses and the UK addendum attached as annexes, and can be accepted without a sales conversation. A counter-signed copy is available for buyers whose process requires one.

Privacy

Is my data used to train models?

No. SynapBridge does not train models on customer content. Where a workspace routes calls to a third-party model provider, that provider's own terms govern their use of the content, which is why the sub-processor register lists each inference provider with a link to their data processing terms and marks them as optional. A workspace can disable any provider it does not want content to reach, and a residency constraint that a provider cannot satisfy blocks the call rather than silently substituting another provider.

Where is my data processed and can I constrain it?

Platform data is processed in the United States. A workspace on the Enterprise tier can constrain which regions its content may be processed in, and the routing decision is made before dispatch and recorded with the call. A provider that cannot satisfy the constraint is not offered to that workspace. Sub-processor processing locations are published per entry on the sub-processor register.

What happens if law enforcement asks for my data?

Customer data belongs to the customer. Valid legal process appropriate to the data sought is required, and requests that are overbroad, defective, or lack jurisdiction are objected to. The affected customer is notified before data is produced unless notification is legally prohibited, in which case we seek to lift or narrow the prohibition and notify as soon as it lapses. Where a customer holds their own keys we cannot produce plaintext, and we say so to the requesting authority. Counts of requests received and actions taken will be published in the semi-annual transparency report.

What happens to my data when I leave?

Workspace deletion removes customer content within the published window. An export in standard formats is available before deletion so nothing has to be abandoned to leave. Per-user deletion is available today and is recorded in the audit trail; an explicit identity verification step on that flow is a committed roadmap item, which is why the retention control is published as partial rather than implemented.

Reliability and incidents

How quickly will you tell me about a security incident?

The clock starts at detection, not at confirmation. A severity one incident gets an initial public update within one hour and hourly updates while it stays open, with a postmortem published within five business days. Severity two is two hours and ten business days. Any incident affecting a specific workspace also goes directly to that workspace's designated security contact within the same window, because the public page alone does not satisfy the commitment. Where a regulation sets a shorter clock, the shorter clock governs and the public update still lands on schedule.

Your incident log is empty. Does that mean nothing has happened?

It means nothing has met the publication threshold since the log opened. That is a thin record rather than a strong one, and the honest reading is that the platform is young. The log is published in this state on purpose: a page that only appears once there is something impressive to put on it is not a transparency surface. The disclosure policy commits to what will appear here, and the commitments were published before there was anything to test them against.

Security

How is my workspace isolated from other customers?

At the database, with row level security in FORCE mode keyed on the workspace identifier. FORCE rather than ENABLE means the policy applies to the table owner as well, and the database user the application connects as does not hold the bypass privilege. A query that fails to bind a workspace returns zero rows rather than every row, so an application bug fails closed. Isolation is a property of the schema rather than a filter the application remembers to apply.

How is data encrypted?

AES-256 at rest across databases, object storage, backups, and log archives. TLS 1.2 or higher in transit on every external connection, with HTTP Strict Transport Security set at the edge. Keys are managed by the cloud key management service, and workspace-scoped keys are available on the Enterprise tier for customers who require a per-workspace key boundary.

Do you run penetration tests?

An independent engagement is committed for the fourth quarter of 2026 and has not yet run, so there is no summary letter to publish. Internal security probes run continuously against the application and infrastructure in the meantime. When the external test completes, the redacted summary with counts by severity and the remediation clock will appear on the reports page, and the full report will be available under NDA.

How do I report a vulnerability?

Email security@synapbridge.com. Acknowledgement within two business days, triage and severity assignment within five, and updates every fourteen days until the report is closed. Remediation targets are seven days for critical, thirty for high, and ninety for medium. Good faith research within the published scope will not be pursued legally, and we will say so if a third party pursues action against a researcher acting within the policy.

Question not answered here

Send it to security@synapbridge.com. Anything asked more than once is added to this page, so the next reviewer finds it without having to ask. That is the whole mechanism by which a trust center reduces the time a security review takes.

Security contactsecurity@synapbridge.com
Privacy contactprivacy@synapbridge.com
Legal and procurementlegal@synapbridge.com