Trust center
Reports and documents
What we publish, what is available under NDA, and what each artifact actually covers. Metadata is never gated: the date, the producing firm, and the headline findings are readable without identifying yourself.
Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.
Completed questionnaire
Consensus Assessment Initiative Questionnaire (CAIQ-Lite)
Available under NDAA completed CAIQ-Lite response covering the Cloud Security Alliance control domains. Answers are drawn from the same control catalog published on this site, so the questionnaire and the public practices page cannot disagree.
Whitepaper
Platform Security Architecture
Open accessHow the platform is built: account separation, the network boundary, where secrets live, how the provider gateway is isolated from the control plane, and what an attacker reaching any one component can and cannot do.
Tenant Isolation Brief
Open accessTenant isolation is enforced at the database with row level security in FORCE mode, not by an application filter. This brief explains what that means, why FORCE rather than ENABLE matters, and how a missing tenant binding fails closed rather than returning another tenant's rows.
AI Governance and Data Handling Brief
Open accessWhat happens to a prompt: the redaction pre-gate, the sovereignty routing decision, which providers see what, what is retained and for how long, and how the audit trail records a call without recording its contents.
Legal and policy documents
Every version is retained. The current version is linked below; superseded versions are available on request so a buyer can confirm which terms applied on a given date.
Privacy Policy
What personal data is collected, the lawful basis for processing it, how long it is kept, and how to exercise data subject rights.
Data Processing Agreement
Processor obligations under GDPR Article 28, with the EU standard contractual clauses and the UK addendum attached as annexes. Available to accept without a negotiation.
Terms of Service
The agreement governing use of the platform. Enterprise customers who need a counter-signed master services agreement can request one.
Sub-processor Register
The current register, with processing locations, transfer mechanisms, and the 30 day change notice commitment.
Available on request
A business associate agreement for healthcare workloads, a mutual non-disclosure agreement for buyers whose counsel requires one rather than the click-through, a security addendum for professional services engagements, and the cyber and errors-and-omissions insurance certificate. Email legal@synapbridge.com. These are listed rather than hidden so a reviewer knows they exist before asking.