Skip to content
Trust Center

Security & Compliance

Your data is your most valuable asset. Here's how we protect it.

Hyves is in early access — here is the honest version

We are a small EU company running a young platform. We hold no security certification of our own and we do not offer a contractual uptime SLA yet. What follows is what we actually do today, not what we intend to do. If your review needs something that is not on this page, ask us and we will tell you straight whether we have it.

Security Practices

Encryption at Rest & In Transit

Data is encrypted at rest with AES-256 and in transit with TLS, on managed Supabase and Vercel infrastructure. Key management is handled by those providers.

Infrastructure Security

Hosted on SOC 2-certified infrastructure — Supabase and Vercel — with their platform-level DDoS protection and monitoring.

Access Controls

Role-based access control across every module, enforced in the database by row-level security rather than in the UI alone.

Responsible Disclosure

We welcome security reports at security@isyncso.com and aim to acknowledge them within 48 hours. There is no paid bounty programme.

Compliance & Certifications

GDPR

How we build

Built and hosted in the EU (Supabase eu-west-1). Lawful basis for B2B outreach, suppression and deletion on request. A DPA is available on request. Compliance is our assessment, not a third party's.

EU AI Act

How we build

We treat the systems we run as in-scope and design for the transparency and human-oversight duties. No conformity assessment has been carried out.

Provider certifications

Held by others

Supabase and Vercel — where your data is stored and served — maintain SOC 2 Type II. That is their certification, not ours.

SOC 2 / ISO 27001

Not held

iSYNCSO holds neither. We will say so here the day an audit actually starts, and publish the report when one is issued.

Data Handling

Data Residency

Your account and its data live in the EU (Supabase eu-west-1). Research and messaging call third-party AI, enrichment and delivery providers, some outside the EU, under the safeguards in our DPA.

Data Retention

Deleting your account removes it and its data from the production database. Provider-side backups age out on their own retention schedules.

Sub-processors

Our DPA lists the providers that process your data — hosting, AI models, enrichment, and delivery. Ask for the current list before you sign; it changes as the stack does.

Your Data, Your Control

Export your account, settings and company record from Settings, and delete your account from the same screen. We do not sell your data or use it to train models.

Questions about security?

Our team is happy to walk you through our security architecture and provide documentation for your compliance reviews.

Contact Security Team