SynapBridge
Sign inGet started

Trust center

Security practices

Every control we operate, what it does, how it is verified, and which framework requirements it maps to. Each entry has a permalink so it can be cited directly in a questionnaire response.

Content published as of 6 Aug 2026. Every claim on these pages links to the control, report, or policy behind it.

Controls published27
Implemented18
Partial6
Planned2
Why the counts are not a percentage.A single completeness score would fold 6 partial and 2 planned controls into an average that reads better than the underlying state. The counts are published separately, and each partial control names what is present and what is missing in its own entry. Every gap with a path to closure appears on the roadmap with a target quarter.

Control domains

AI governance (3)Application security (2)Business continuity (2)Data handling (4)Encryption and key management (3)Identity and access (3)Logging and monitoring (1)Network (1)Personnel (1)Physical and environmental (1)Tenant isolation (2)Vendor management (1)Vulnerability management (3)

AI governance

Tamper-evident audit trail

ai-governance.audit-trail
Implemented

Every model call, policy decision, and administrative action is recorded in an append-only audit trail with a hash chain, so a deleted or altered entry is detectable.

Records capture who, what, when, which model, which policy applied, and the outcome. Prompt and completion bodies are not stored in the audit trail; the trail records that a call happened and how it was governed.

SOC2 CC7.2HIPAA 164.312(b)EU AI Act Art. 12NIST AI RMF Govern
VerifiedContinuously
Last verified5 Aug 2026

Model and use case registry

ai-governance.model-registry
Implemented

Models available to a workspace are registered with their provider, region, and entitlement. AI use cases are registered with an owner, a risk classification, and the models bound to them.

A model that is not registered cannot be called. Use case registration is what makes the record-keeping obligations answerable without a manual survey.

EU AI Act Art. 11NIST AI RMF MapISO 42001
VerifiedOn change
Last verified25 Jul 2026

Model bias and quality evaluation

ai-governance.bias-evaluation
Partial

Evaluation runs score model outputs against defined criteria and record the result against the model card.

The evaluation runner and model cards are in place. A standing bias evaluation suite with published methodology is a roadmap item, so this control is marked partial rather than implemented.

EU AI Act Art. 15NIST AI RMF Measure
VerifiedQuarterly
Last verified10 Jul 2026

Application security

Implemented

A strict content security policy is served on every application response. Inline script is blocked and styles are served from stylesheets rather than inline attributes.

The policy is nonce-based. It is enforced rather than report-only, and violations are reported to an internal collector.

SOC2 CC7.1ISO 27001 A.8.26
VerifiedContinuously
Last verified1 Aug 2026

Secure development lifecycle

application.secure-sdlc
Implemented

Every change goes through pull request review, automated static analysis, dependency vulnerability scanning, secret scanning, and a security-focused review gate before it can reach production.

Static analysis and dependency scanning run on every pull request and block the merge on a high severity finding. Direct pushes to the release branch are not permitted.

SOC2 CC8.1ISO 27001 A.8.25NIST AI RMF Manage
VerifiedContinuously
Last verified5 Aug 2026

Business continuity

Backup and point-in-time recovery

business-continuity.backups
Implemented

Automated backups with point-in-time recovery. Backups are encrypted and retained according to the published schedule.

Restore procedures are documented. Recovery time and recovery point targets are published on the reliability page.

SOC2 A1.2HIPAA 164.308(a)(7)ISO 27001 A.8.13
VerifiedDaily
Last verified6 Aug 2026
Planned

A periodic exercise that restores from backup into a clean environment and measures the result against the published recovery targets.

Backups exist and restore procedures are documented, but a full exercise has not been run. This is the most significant open gap on this page and it is published as a roadmap commitment with a target quarter rather than being described in softer terms.

SOC2 A1.3HIPAA 164.308(a)(7)(ii)(D)ISO 27001 A.5.30
VerifiedAnnually
Last verifiedNot yet verified

Data handling

Sensitive data redaction before provider dispatch

data-handling.redaction-pre-gate
Implemented

Prompts are scanned for sensitive data classes before they leave the platform for a model provider. Detected content is redacted, blocked, or quarantined according to workspace policy.

The scan runs as a pre-gate, ahead of the provider call, so a blocked prompt is never transmitted. Detector coverage and thresholds are configurable per workspace and every decision is recorded in the audit trail.

HIPAA 164.312(b)GDPR Art. 32ISO 27001 A.8.12
VerifiedContinuously
Last verified5 Aug 2026

Retention and deletion

data-handling.retention
Partial

Retention periods are set per data class and per workspace. Workspace deletion removes customer content within the published window.

Per-user deletion is available and is recorded in the audit trail. An explicit identity verification step on the per-user flow is a published roadmap item and is not yet in place, which is why this control is marked partial rather than implemented.

GDPR Art. 17SOC2 CC6.5ISO 27001 A.8.10
VerifiedQuarterly
Last verified1 Jul 2026

Data portability and export

data-handling.portability
Partial

Workspace data can be exported in standard formats. The export covers conversations, memory graph facts, audit records, and configuration.

Export is self-serve on the Business tier. Exposing the same capability as a subject access request endpoint is a published roadmap item, so this control is marked partial.

GDPR Art. 20ISO 27001 A.8.10
VerifiedQuarterly
Last verified1 Jul 2026
Available fromBusiness plan

Data residency and sovereignty routing

data-handling.residency
Implemented

A workspace can constrain which regions its data may be processed in. A model provider that cannot satisfy the constraint is not offered for that workspace rather than being silently substituted.

The routing decision is made before dispatch and is recorded with the call. A constraint that cannot be satisfied fails the call with an explicit reason instead of falling back.

GDPR Art. 44ISO 27001 A.5.34
VerifiedContinuously
Last verified1 Aug 2026
Available fromEnterprise plan

Encryption and key management

Encryption at rest

encryption.at-rest
Implemented

All customer data at rest is encrypted with AES-256. Databases, object storage, backups, and log archives are covered.

Keys are managed by the cloud key management service. Workspace-scoped keys are available on the Enterprise tier for customers who require a per-workspace key boundary.

SOC2 CC6.1HIPAA 164.312(a)(2)(iv)ISO 27001 A.8.24
VerifiedContinuously
Last verified1 Aug 2026

Encryption in transit

encryption.in-transit
Implemented

TLS 1.2 or higher on every external connection, with modern cipher suites only. Internal service-to-service traffic is encrypted on the same terms.

HTTP Strict Transport Security is set at the edge. Plain HTTP is redirected rather than served.

SOC2 CC6.7HIPAA 164.312(e)(1)ISO 27001 A.8.24
VerifiedContinuously
Last verified1 Aug 2026
Implemented

Application secrets and customer-supplied provider credentials are held in a managed secrets store, encrypted with a dedicated key, and are never written to source control or to logs.

Customer-supplied provider keys live under a per-workspace path so a grant cannot be written broadly enough to reach another workspace's credentials. Automated scanning blocks a commit that would introduce a credential.

SOC2 CC6.1ISO 27001 A.8.24
VerifiedContinuously
Last verified4 Aug 2026

Identity and access

Multi-factor authentication

identity.mfa-enforcement
Implemented

Multi-factor authentication is available on every account and can be required at the workspace level by an administrator. Enrolment supports authenticator apps and hardware security keys.

Enrolment is bound to a short-lived server-issued cookie so a secret cannot be silently generated for a session that never completed the flow. Backup codes are single use and hashed at rest.

SOC2 CC6.1HIPAA 164.312(d)ISO 27001 A.5.17
VerifiedContinuously
Last verified1 Aug 2026

Federated single sign-on and directory sync

identity.sso-scim
Implemented

SAML and OIDC single sign-on with SCIM directory provisioning. Custom claims that carry workspace scope are read from the access token, not the identity token.

Identity is brokered so a customer can federate a multi-tenant corporate directory without us holding a per-customer connection secret.

SOC2 CC6.1ISO 27001 A.5.16
VerifiedOn change
Last verified28 Jul 2026
Available fromBusiness plan

Session lifetime and revocation

identity.session-lifetime
Implemented

Sessions use a sliding expiry and are bound to an opaque server-side identifier rather than a self-contained token, so a session can be revoked immediately rather than waiting for it to expire.

Session records live in a dedicated store. Revoking a session deletes the record; the cookie alone grants nothing.

SOC2 CC6.1ISO 27001 A.8.5
VerifiedContinuously
Last verified1 Aug 2026

Logging and monitoring

Centralised logging and alerting

logging-monitoring.centralised-logging
Implemented

Application, infrastructure, and access logs are centralised with defined retention. Alarms cover error rate, latency, authorisation failures, and cost anomalies.

Log groups have explicit retention rather than defaulting to indefinite. Alarms notify an on-call rotation.

SOC2 CC7.2HIPAA 164.312(b)ISO 27001 A.8.15
VerifiedContinuously
Last verified1 Aug 2026

Network

Edge protection and rate limiting

network.edge-protection
Implemented

Public surfaces sit behind a content delivery network with a web application firewall, managed rule groups, and rate-based rules. Origins are not directly reachable.

Rate limits are applied per endpoint class rather than globally, so an abusive caller on one path does not degrade another.

SOC2 CC6.6ISO 27001 A.8.20
VerifiedContinuously
Last verified1 Aug 2026

Personnel

Least privilege and access review

personnel.access-review
Partial

Access to production systems is granted on the principle of least privilege and is reviewed periodically. Access is removed on role change and on departure.

Production access requires multi-factor authentication and is recorded. A formalised quarterly review cadence with a signed record is pending, so this control is marked partial.

SOC2 CC6.2SOC2 CC6.3HIPAA 164.308(a)(3)ISO 27001 A.5.18
VerifiedQuarterly
Last verified1 Jul 2026

Physical and environmental

Physical and environmental controls

physical.cloud-shared-responsibility
Not applicable

Physical security of the underlying data centres is provided by the cloud infrastructure provider under the shared responsibility model.

SynapBridge operates no data centre and holds no customer data on physical media. The provider's own third-party attestations cover this domain, and their reports are available directly from them.

HIPAA 164.310(a)SOC2 CC6.4ISO 27001 A.7.1
VerifiedAnnually
Last verified1 Jul 2026

Tenant isolation

Database row level security in FORCE mode

tenant-isolation.row-level-security
Implemented

Every table holding customer data carries row level security in FORCE mode, keyed on the workspace identifier. A query that does not bind a workspace returns zero rows rather than every row.

FORCE rather than ENABLE means the policy applies to the table owner as well. The database user the application connects as does not hold the bypass privilege, so a scoping bug in application code cannot read across workspaces.

SOC2 CC6.1SOC2 CC6.7HIPAA 164.312(a)(1)ISO 27001 A.8.3
VerifiedContinuously
Last verified5 Aug 2026

Account and environment separation

tenant-isolation.account-separation
Implemented

Production, staging, and development run in separate cloud accounts with no shared credentials and no network path between them. Deployment to production requires a separate approval from deployment to any other environment.

Cross-account access is granted by resource policy for named roles and specific resources, never by a shared credential.

SOC2 CC6.6SOC2 CC8.1ISO 27001 A.8.31
VerifiedOn change
Last verified30 Jul 2026

Vendor management

Sub-processor assessment and change notice

vendor-management.subprocessor-review
Partial

Sub-processors are assessed before onboarding and the register is published. Customers receive at least 30 days notice before a new sub-processor begins processing.

The register is the source of truth and the notice date is recorded per entry. A formalised annual reassessment cadence is pending, so this control is marked partial.

GDPR Art. 28SOC2 CC9.2ISO 27001 A.5.19
VerifiedAnnually
Last verified1 Jul 2026

Vulnerability management

Dependency and container scanning

vulnerability-management.dependency-scanning
Partial

Dependencies are scanned continuously for known vulnerabilities. Container images are scanned before they can be deployed.

A high or critical finding blocks the merge. A software bill of materials published per release is a roadmap item.

SOC2 CC7.1ISO 27001 A.8.8NIST SR
VerifiedContinuously
Last verified5 Aug 2026

Independent penetration testing

vulnerability-management.penetration-testing
Planned

Annual third-party penetration testing, plus a test on any major architecture change.

The first engagement has not yet run. This control is published as planned rather than implemented, and the summary letter will appear in the reports library when it exists. Internal security probes run continuously in the meantime.

SOC2 CC7.1ISO 27001 A.8.8
VerifiedAnnually
Last verifiedNot yet verified

Coordinated vulnerability disclosure

vulnerability-management.disclosure
Implemented

A published disclosure policy with a stated scope, a safe harbour commitment, and response time commitments by severity. Reports go to security@synapbridge.com.

Acknowledgement within two business days, triage within five, and a remediation target of seven days for critical findings. A paid bounty programme is a roadmap item and is not claimed here, because a bounty that does not pay costs more credibility than it earns.

SOC2 CC7.4ISO 27001 A.5.7
VerifiedAnnually
Last verified20 Jul 2026

Answering a questionnaire

Each control anchor is a stable URL. Linking /trust-center/security#identity.mfa-enforcement from a questionnaire response gives the reviewer the answer and its source in one click, and the answer stays correct when the control changes because the page is the source rather than a copy of it.

A completed CAIQ-Lite response drawn from this same catalog is available under NDA on the reports page. Because it is generated from these entries, the questionnaire and this page cannot disagree.

Security contactsecurity@synapbridge.com
Privacy contactprivacy@synapbridge.com
Legal and procurementlegal@synapbridge.com