Trust and compliance

Security, compliance,

and data handling.

Enterprise buyers, along with their procurement and security teams, need a clear understanding of how Syncura manages data before moving forward. This page outlines our security posture, compliance status, and data handling practices.

Compliance & certifications

Our compliance posture

Syncura is designed to meet the compliance requirements of the enterprise clients we serve. Below is a clear summary of our status.

Aligned

SOC 2 Type II

Syncura's security controls are designed and operated against the AICPA Trust Services Criteria for security, availability, and confidentiality, alongside ISO/IEC 27001 principles and the NIST Cybersecurity Framework. Syncura does not hold SOC 2 or ISO 27001 certification. The measures Syncura commits to contractually are published as Annex B to the Data Processing Agreement.

Read Annex B →

DPA published

GDPR

Syncura supports customer compliance with GDPR. We process personal data only as required to deliver our services and support data subject rights. For customers operating under GDPR, Syncura acts as a data processor under its Data Processing Agreement, which is published in full and incorporated by reference into the SaaS Subscription Agreement. Annex A lists Syncura's subprocessors; Annex B sets out the technical and organisational measures.

Read the DPA →

US East

Data residency

Customer data is processed and stored on Amazon Web Services in the United States (US East region). Syncura does not currently offer alternative processing regions. Subprocessors and their processing locations are set out in Annex A to the Data Processing Agreement.

Read Annex A →

In place

Encryption

All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Encryption keys are managed through industry-standard key management services and rotate regularly.

In place

Access controls

Access to customer data is restricted based on the principle of least privilege. All access is logged and audited. Multi-factor authentication is required for system access. Access rights are reviewed regularly and updated when roles change.

In place

Security governance

Security is treated as an architectural principle rather than a bolt-on, with responsibility shared across engineering, operations and leadership. The programme is built on least-privilege access, defence in depth, separation of customer environments, and continuous monitoring and improvement.

In place

Environment isolation

Customer environments are logically isolated from one another, and processing, storage and management systems are segmented. Syncura is delivered as a hosted service only; there is no customer-hosted deployment option.

Under evaluation

Assurance and testing

Syncura has not, to date, engaged a third party to perform penetration testing or an independent security assessment of the service. Independent security testing is under evaluation and no cadence has been established. Syncura will make available the information reasonably necessary to demonstrate compliance with its Data Processing Agreement; formal on-site audits are excluded unless required by law.

Data handling

How we handle your data

What data we process

Syncura processes the documents and data you provide as part of your use of the platform. This includes document content, associated metadata, and usage data generated during operation. We process only the data required to deliver the contracted service.

How your data is used

Your data is used solely to provide the Syncura service you have contracted for. We do not use client data to train shared models, sell data to third parties, or use it for any purpose outside the scope of your agreement.

Data retention

Customer data is retained only as long as necessary to provide the service, except as configured by the customer or required by law. Retention is configurable and is agreed during onboarding. On termination, customer data is deleted or returned within 30 days unless a longer period is required by law or agreed in writing. Limited non-content metadata is retained for usage metering, billing, security, and service integrity.

Subprocessors

Amazon Web Services (US East region) is currently Syncura's sole subprocessor. The full list, with the service provided and processing location for each, is published as Annex A to the Data Processing Agreement. Customers receive at least 30 days' notice before Syncura engages a new subprocessor, and may object on reasonable data-protection grounds.

Read Annex A →

Availability and resilience

Customer data is hosted on managed database infrastructure with a standby replica alongside the primary database. Full backups are taken nightly from the standby replica so backup activity does not affect production, and transaction logs stream continuously to object storage, supporting point-in-time restoration between backups. Failover and restoration have been tested; no fixed testing schedule has been established. Syncura has not defined a Recovery Point Objective or Recovery Time Objective, and none is committed.

Incident response

Syncura monitors continuously for suspicious activity and maintains documented incident response procedures with defined escalation paths. Where a personal data breach occurs, Syncura notifies the customer without undue delay and in any event within seventy-two hours of becoming aware of it, with the information the customer needs to meet its own notification obligations.

What we rely on you for

Security is shared. Customers are responsible for determining whether the service suits their use case, configuring workflows and validation controls, managing user access and credentials, reviewing outputs before relying on them, and setting appropriate retention and governance policies for the documents they process.

Security questions or

documentation requests?

This page is Syncura's security documentation — there is no separate overview document to request. Our contractual security terms are published in the Data Processing Agreement and its annexes on the Legal page. For questionnaires or anything not covered here, reach out directly.

Talk to us firstBook a demo