Security Overview
Last updated: September 30, 2026
This page describes only controls that exist in the product today.
Certifications. Synseus does not hold a SOC 2 report or any other third-party certification, and no audit is under way.
What is in place
| Area | What is in place |
|---|---|
| Hosting | Vercel, United States (Washington, D.C. region); HTTPS for all traffic |
| Database | Supabase-managed PostgreSQL, United States (Oregon region) |
| Passwords | Stored only as bcrypt hashes (cost 12) |
| Integration credentials | Encrypted with AES-256-GCM through a single code path; if the key is missing or invalid, nothing is stored. No integrations are offered today, and none are stored. |
| Client data | Not collected through connections: CRM and calendar connections are not offered |
| Lead forms | Submissions to a customer's lead forms are stored with the submitter's IP address and browser details; they are emailed to addresses the customer sets, sent to webhook addresses the customer sets, and, if the customer turns on an auto-reply, answered by email to the submitter |
| Text messages | Twilio is in the code; phone verification is switched off (the route that sends verification texts refuses every request), and no page adds or verifies a phone number |
| Access control | Role-based access for multi-seat firms; actions Synseus administrators take in the admin tools to view, create, edit or delete a user account, add account notes, start or end impersonation of a user, view a user's billing, create an invoice, issue a refund, activate an enterprise plan, or update, reply to or delete a support ticket logged with IP address and browser details; when an account is deleted at its owner's request, log entries about it keep no name or email address |
| AI | One provider (Anthropic) through a single code path; every request carries an instruction never to invent a figure |
| Fonts | Served from synseus.com; the site makes no font requests to Google |
| Analytics | Google Tag Manager / Analytics, loaded only after a visitor allows analytics cookies |
| Payments | Stripe; Synseus stores no card numbers or card details |
| Error reporting | Sentry is installed but not switched on; no error data leaves the product |
| Breach response | Customer notification within 72 hours, as set out on our compliance page |
| Deletion and export | Self-service in Settings → Privacy & Data: export is prepared at once; deletion is confirmed by email and carried out by a daily scheduled job on or after the 30th day after the request, or at the next run after confirmation if that is later; deleting an account cancels its Stripe subscription first, and if Stripe cannot confirm the cancellation the account is not deleted until it can |
Not in place, and not claimed
Penetration testing; a retention schedule beyond deletion on request; removal of personal information before AI requests (no client records are held through connections); a public health endpoint for monitoring; error reporting.
Contact
Security questions, vulnerability reports and compliance questions: [email protected]. Messages to this address reach our team directly and are tracked as support tickets. We respond to compliance questions within one business day and will complete a reasonable vendor risk assessment on request.