SynapBridge
Sign inGet started

Trust center

Reports and documents

What we publish, what is available under NDA, and what each artifact actually covers. Metadata is never gated: the date, the producing firm, and the headline findings are readable without identifying yourself.

Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.

How access works.Anything marked open access is linked directly on this page. Anything marked available under NDA is released through a request that takes a work email, a click-through non-disclosure agreement scoped narrowly to reviewing the report, and a download link minted per click rather than emailed. A presigned link is never sent in an email or embedded in a shareable URL, because a forwarded email would turn a gated report into a public one. Email security@synapbridge.com to start a request.
No penetration test report is available yet.The first independent engagement is a committed roadmap item for the fourth quarter of 2026. When it completes, the redacted summary letter with counts by severity and the remediation clock will be published on this page as open access, and the full report will be available under NDA. Internal security probes run continuously in the meantime, but an internal probe is not an independent test and this page will not describe it as one.

Completed questionnaire

Consensus Assessment Initiative Questionnaire (CAIQ-Lite)

Available under NDA

A completed CAIQ-Lite response covering the Cloud Security Alliance control domains. Answers are drawn from the same control catalog published on this site, so the questionnaire and the public practices page cannot disagree.

Produced bySynapBridge
Published30 Jul 2026

Request this report

Whitepaper

Platform Security Architecture

Open access

How the platform is built: account separation, the network boundary, where secrets live, how the provider gateway is isolated from the control plane, and what an attacker reaching any one component can and cannot do.

Produced bySynapBridge
Published15 Jul 2026

Read Platform Security Architecture

Tenant Isolation Brief

Open access

Tenant isolation is enforced at the database with row level security in FORCE mode, not by an application filter. This brief explains what that means, why FORCE rather than ENABLE matters, and how a missing tenant binding fails closed rather than returning another tenant's rows.

Produced bySynapBridge
Published15 Jul 2026

Read Tenant Isolation Brief

AI Governance and Data Handling Brief

Open access

What happens to a prompt: the redaction pre-gate, the sovereignty routing decision, which providers see what, what is retained and for how long, and how the audit trail records a call without recording its contents.

Produced bySynapBridge
Published20 Jul 2026

Read AI Governance and Data Handling Brief

Every version is retained. The current version is linked below; superseded versions are available on request so a buyer can confirm which terms applied on a given date.

Privacy Policy

What personal data is collected, the lawful basis for processing it, how long it is kept, and how to exercise data subject rights.

Version2026-07-14
Effective14 Jul 2026
AcceptancePublished for download

Read Privacy Policy

Data Processing Agreement

Processor obligations under GDPR Article 28, with the EU standard contractual clauses and the UK addendum attached as annexes. Available to accept without a negotiation.

Version2026-07-14
Effective14 Jul 2026
AcceptanceAccept online, no negotiation required

Read Data Processing Agreement

Terms of Service

The agreement governing use of the platform. Enterprise customers who need a counter-signed master services agreement can request one.

Version2026-07-14
Effective14 Jul 2026
AcceptancePublished for download

Read Terms of Service

Sub-processor Register

The current register, with processing locations, transfer mechanisms, and the 30 day change notice commitment.

Version2026-08-06
Effective6 Aug 2026
AcceptancePublished for download

Read Sub-processor Register

Available on request

A business associate agreement for healthcare workloads, a mutual non-disclosure agreement for buyers whose counsel requires one rather than the click-through, a security addendum for professional services engagements, and the cyber and errors-and-omissions insurance certificate. Email legal@synapbridge.com. These are listed rather than hidden so a reviewer knows they exist before asking.

Security contactsecurity@synapbridge.com
Privacy contactprivacy@synapbridge.com
Legal and procurementlegal@synapbridge.com