Security Overview

Last updated: September 30, 2026

This page describes only controls that exist in the product today.

Certifications. Synseus does not hold a SOC 2 report or any other third-party certification, and no audit is under way.

What is in place

AreaWhat is in place
HostingVercel, United States (Washington, D.C. region); HTTPS for all traffic
DatabaseSupabase-managed PostgreSQL, United States (Oregon region)
PasswordsStored only as bcrypt hashes (cost 12)
Integration credentialsEncrypted with AES-256-GCM through a single code path; if the key is missing or invalid, nothing is stored. No integrations are offered today, and none are stored.
Client dataNot collected through connections: CRM and calendar connections are not offered
Lead formsSubmissions to a customer's lead forms are stored with the submitter's IP address and browser details; they are emailed to addresses the customer sets, sent to webhook addresses the customer sets, and, if the customer turns on an auto-reply, answered by email to the submitter
Text messagesTwilio is in the code; phone verification is switched off (the route that sends verification texts refuses every request), and no page adds or verifies a phone number
Access controlRole-based access for multi-seat firms; actions Synseus administrators take in the admin tools to view, create, edit or delete a user account, add account notes, start or end impersonation of a user, view a user's billing, create an invoice, issue a refund, activate an enterprise plan, or update, reply to or delete a support ticket logged with IP address and browser details; when an account is deleted at its owner's request, log entries about it keep no name or email address
AIOne provider (Anthropic) through a single code path; every request carries an instruction never to invent a figure
FontsServed from synseus.com; the site makes no font requests to Google
AnalyticsGoogle Tag Manager / Analytics, loaded only after a visitor allows analytics cookies
PaymentsStripe; Synseus stores no card numbers or card details
Error reportingSentry is installed but not switched on; no error data leaves the product
Breach responseCustomer notification within 72 hours, as set out on our compliance page
Deletion and exportSelf-service in Settings → Privacy & Data: export is prepared at once; deletion is confirmed by email and carried out by a daily scheduled job on or after the 30th day after the request, or at the next run after confirmation if that is later; deleting an account cancels its Stripe subscription first, and if Stripe cannot confirm the cancellation the account is not deleted until it can

Not in place, and not claimed

Penetration testing; a retention schedule beyond deletion on request; removal of personal information before AI requests (no client records are held through connections); a public health endpoint for monitoring; error reporting.

Contact

Security questions, vulnerability reports and compliance questions: [email protected]. Messages to this address reach our team directly and are tracked as support tickets. We respond to compliance questions within one business day and will complete a reasonable vendor risk assessment on request.