SynseusCCO Resource Center

Vendor Due Diligence Vault

Compliance Information for Your CCO

What Synseus stores, where AI requests go, and how a data incident is notified to firms.

Data Architecture

What We Store vs. What We Don't

What Synseus stores

  • Practice-level analytics data and assessment responses
  • Public SEC/IAPD regulatory filing data, stored per firm (for example firm name, CRD number, address, phone number and assets under management)
  • Usage metrics and platform activity logs
  • Subscription and billing records (via Stripe — no card data stored), including copies of Stripe billing events, some of which contain the customer's name, email address and billing address

What Synseus does NOT store

  • Client investment holdings or transaction history

Encryption: All data in transit is protected by TLS 1.2 or higher. CRM connections, including Wealthbox and Redtail, are not offered today and cannot be started, so no integration credentials are stored. The code that would store them encrypts them with AES-256-GCM.

AI Processing

Where AI Requests Go

AI inference runs on Anthropic's Claude API under our data processing terms — prompts are not used to train models.

Regulation S-P

Regulation S-P — 72-Hour Incident Notification

Under the SEC's amended Regulation S-P (adopted May 16, 2024 and effective August 2, 2024; larger entities must comply by December 3, 2025 and smaller entities by June 3, 2026), covered institutions must notify affected individuals of a data breach within 30 days, and must require their service providers to notify them within 72 hours of becoming aware of a breach. Synseus is a technology vendor to RIAs. If an incident affects your firm's data, we will notify you as described below.

1

Detection & Containment

When we detect a potential incident, we contain it and investigate the cause.

2

Customer Notification — Within 72 Hours

Affected firm administrators receive a direct email from [email protected] within 72 hours of confirmed breach, including: nature of the incident, data categories involved, immediate remediation steps taken, and recommended actions for the firm's CCO.

3

Regulatory Support & Post-Incident Summary

After an incident, Synseus provides a written summary of the cause and the steps taken, for your firm's records.

Questions?

Our compliance team responds within one business day

Whether you need a custom questionnaire completed, a vendor risk assessment, or a live call with our security team — we're here.

[email protected]