Trust center
Security practices
Every control we operate, what it does, how it is verified, and which framework requirements it maps to. Each entry has a permalink so it can be cited directly in a questionnaire response.
Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.
Control domains
AI governance
Tamper-evident audit trail
ai-governance.audit-trailEvery model call, policy decision, and administrative action is recorded in an append-only audit trail with a hash chain, so a deleted or altered entry is detectable.
Records capture who, what, when, which model, which policy applied, and the outcome. Prompt and completion bodies are not stored in the audit trail; the trail records that a call happened and how it was governed.
Model and use case registry
ai-governance.model-registryModels available to a workspace are registered with their provider, region, and entitlement. AI use cases are registered with an owner, a risk classification, and the models bound to them.
A model that is not registered cannot be called. Use case registration is what makes the record-keeping obligations answerable without a manual survey.
Model bias and quality evaluation
ai-governance.bias-evaluationEvaluation runs score model outputs against defined criteria and record the result against the model card.
The evaluation runner and model cards are in place. A standing bias evaluation suite with published methodology is a roadmap item, so this control is marked partial rather than implemented.
Application security
Content security policy
application.content-security-policyA strict content security policy is served on every application response. Inline script is blocked and styles are served from stylesheets rather than inline attributes.
The policy is nonce-based. It is enforced rather than report-only, and violations are reported to an internal collector.
Secure development lifecycle
application.secure-sdlcEvery change goes through pull request review, automated static analysis, dependency vulnerability scanning, secret scanning, and a security-focused review gate before it can reach production.
Static analysis and dependency scanning run on every pull request and block the merge on a high severity finding. Direct pushes to the release branch are not permitted.
Business continuity
Backup and point-in-time recovery
business-continuity.backupsAutomated backups with point-in-time recovery. Backups are encrypted and retained according to the published schedule.
Restore procedures are documented. Recovery time and recovery point targets are published on the reliability page.
Disaster recovery exercise
business-continuity.disaster-recovery-testingA periodic exercise that restores from backup into a clean environment and measures the result against the published recovery targets.
Backups exist and restore procedures are documented, but a full exercise has not been run. This is the most significant open gap on this page and it is published as a roadmap commitment with a target quarter rather than being described in softer terms.
Data handling
Sensitive data redaction before provider dispatch
data-handling.redaction-pre-gatePrompts are scanned for sensitive data classes before they leave the platform for a model provider. Detected content is redacted, blocked, or quarantined according to workspace policy.
The scan runs as a pre-gate, ahead of the provider call, so a blocked prompt is never transmitted. Detector coverage and thresholds are configurable per workspace and every decision is recorded in the audit trail.
Retention and deletion
data-handling.retentionRetention periods are set per data class and per workspace. Workspace deletion removes customer content within the published window.
Per-user deletion is available and is recorded in the audit trail. An explicit identity verification step on the per-user flow is a published roadmap item and is not yet in place, which is why this control is marked partial rather than implemented.
Data portability and export
data-handling.portabilityWorkspace data can be exported in standard formats. The export covers conversations, memory graph facts, audit records, and configuration.
Export is self-serve on the Business tier. Exposing the same capability as a subject access request endpoint is a published roadmap item, so this control is marked partial.
Data residency and sovereignty routing
data-handling.residencyA workspace can constrain which regions its data may be processed in. A model provider that cannot satisfy the constraint is not offered for that workspace rather than being silently substituted.
The routing decision is made before dispatch and is recorded with the call. A constraint that cannot be satisfied fails the call with an explicit reason instead of falling back.
Encryption and key management
Encryption at rest
encryption.at-restAll customer data at rest is encrypted with AES-256. Databases, object storage, backups, and log archives are covered.
Keys are managed by the cloud key management service. Workspace-scoped keys are available on the Enterprise tier for customers who require a per-workspace key boundary.
Encryption in transit
encryption.in-transitTLS 1.2 or higher on every external connection, with modern cipher suites only. Internal service-to-service traffic is encrypted on the same terms.
HTTP Strict Transport Security is set at the edge. Plain HTTP is redirected rather than served.
Secrets management
encryption.secrets-managementApplication secrets and customer-supplied provider credentials are held in a managed secrets store, encrypted with a dedicated key, and are never written to source control or to logs.
Customer-supplied provider keys live under a per-workspace path so a grant cannot be written broadly enough to reach another workspace's credentials. Automated scanning blocks a commit that would introduce a credential.
Identity and access
Multi-factor authentication
identity.mfa-enforcementMulti-factor authentication is available on every account and can be required at the workspace level by an administrator. Enrolment supports authenticator apps and hardware security keys.
Enrolment is bound to a short-lived server-issued cookie so a secret cannot be silently generated for a session that never completed the flow. Backup codes are single use and hashed at rest.
Federated single sign-on and directory sync
identity.sso-scimSAML and OIDC single sign-on with SCIM directory provisioning. Custom claims that carry workspace scope are read from the access token, not the identity token.
Identity is brokered so a customer can federate a multi-tenant corporate directory without us holding a per-customer connection secret.
Session lifetime and revocation
identity.session-lifetimeSessions use a sliding expiry and are bound to an opaque server-side identifier rather than a self-contained token, so a session can be revoked immediately rather than waiting for it to expire.
Session records live in a dedicated store. Revoking a session deletes the record; the cookie alone grants nothing.
Logging and monitoring
Centralised logging and alerting
logging-monitoring.centralised-loggingApplication, infrastructure, and access logs are centralised with defined retention. Alarms cover error rate, latency, authorisation failures, and cost anomalies.
Log groups have explicit retention rather than defaulting to indefinite. Alarms notify an on-call rotation.
Network
Edge protection and rate limiting
network.edge-protectionPublic surfaces sit behind a content delivery network with a web application firewall, managed rule groups, and rate-based rules. Origins are not directly reachable.
Rate limits are applied per endpoint class rather than globally, so an abusive caller on one path does not degrade another.
Personnel
Least privilege and access review
personnel.access-reviewAccess to production systems is granted on the principle of least privilege and is reviewed periodically. Access is removed on role change and on departure.
Production access requires multi-factor authentication and is recorded. A formalised quarterly review cadence with a signed record is pending, so this control is marked partial.
Physical and environmental
Physical security of the underlying data centres is provided by the cloud infrastructure provider under the shared responsibility model.
SynapBridge operates no data centre and holds no customer data on physical media. The provider's own third-party attestations cover this domain, and their reports are available directly from them.
Tenant isolation
Database row level security in FORCE mode
tenant-isolation.row-level-securityEvery table holding customer data carries row level security in FORCE mode, keyed on the workspace identifier. A query that does not bind a workspace returns zero rows rather than every row.
FORCE rather than ENABLE means the policy applies to the table owner as well. The database user the application connects as does not hold the bypass privilege, so a scoping bug in application code cannot read across workspaces.
Account and environment separation
tenant-isolation.account-separationProduction, staging, and development run in separate cloud accounts with no shared credentials and no network path between them. Deployment to production requires a separate approval from deployment to any other environment.
Cross-account access is granted by resource policy for named roles and specific resources, never by a shared credential.
Vendor management
Sub-processor assessment and change notice
vendor-management.subprocessor-reviewSub-processors are assessed before onboarding and the register is published. Customers receive at least 30 days notice before a new sub-processor begins processing.
The register is the source of truth and the notice date is recorded per entry. A formalised annual reassessment cadence is pending, so this control is marked partial.
Vulnerability management
Dependency and container scanning
vulnerability-management.dependency-scanningDependencies are scanned continuously for known vulnerabilities. Container images are scanned before they can be deployed.
A high or critical finding blocks the merge. A software bill of materials published per release is a roadmap item.
Independent penetration testing
vulnerability-management.penetration-testingAnnual third-party penetration testing, plus a test on any major architecture change.
The first engagement has not yet run. This control is published as planned rather than implemented, and the summary letter will appear in the reports library when it exists. Internal security probes run continuously in the meantime.
Coordinated vulnerability disclosure
vulnerability-management.disclosureA published disclosure policy with a stated scope, a safe harbour commitment, and response time commitments by severity. Reports go to security@synapbridge.com.
Acknowledgement within two business days, triage within five, and a remediation target of seven days for critical findings. A paid bounty programme is a roadmap item and is not claimed here, because a bounty that does not pay costs more credibility than it earns.
Answering a questionnaire
Each control anchor is a stable URL. Linking /trust-center/security#identity.mfa-enforcement from a questionnaire response gives the reviewer the answer and its source in one click, and the answer stays correct when the control changes because the page is the source rather than a copy of it.
A completed CAIQ-Lite response drawn from this same catalog is available under NDA on the reports page. Because it is generated from these entries, the questionnaire and this page cannot disagree.