Security & Compliance
Your data is your most valuable asset. Here's how we protect it.
We are a small EU company running a young platform. We hold no security certification of our own and we do not offer a contractual uptime SLA yet. What follows is what we actually do today, not what we intend to do. If your review needs something that is not on this page, ask us and we will tell you straight whether we have it.
Security Practices
Encryption at Rest & In Transit
Data is encrypted at rest with AES-256 and in transit with TLS, on managed Supabase and Vercel infrastructure. Key management is handled by those providers.
Infrastructure Security
Hosted on SOC 2-certified infrastructure — Supabase and Vercel — with their platform-level DDoS protection and monitoring.
Access Controls
Role-based access control across every module, enforced in the database by row-level security rather than in the UI alone.
Responsible Disclosure
We welcome security reports at security@isyncso.com and aim to acknowledge them within 48 hours. There is no paid bounty programme.
Compliance & Certifications
GDPR
How we buildBuilt and hosted in the EU (Supabase eu-west-1). Lawful basis for B2B outreach, suppression and deletion on request. A DPA is available on request. Compliance is our assessment, not a third party's.
EU AI Act
How we buildWe treat the systems we run as in-scope and design for the transparency and human-oversight duties. No conformity assessment has been carried out.
Provider certifications
Held by othersSupabase and Vercel — where your data is stored and served — maintain SOC 2 Type II. That is their certification, not ours.
SOC 2 / ISO 27001
Not heldiSYNCSO holds neither. We will say so here the day an audit actually starts, and publish the report when one is issued.
Data Handling
Data Residency
Your account and its data live in the EU (Supabase eu-west-1). Research and messaging call third-party AI, enrichment and delivery providers, some outside the EU, under the safeguards in our DPA.
Data Retention
Deleting your account removes it and its data from the production database. Provider-side backups age out on their own retention schedules.
Sub-processors
Our DPA lists the providers that process your data — hosting, AI models, enrichment, and delivery. Ask for the current list before you sign; it changes as the stack does.
Your Data, Your Control
Export your account, settings and company record from Settings, and delete your account from the same screen. We do not sell your data or use it to train models.
Questions about security?
Our team is happy to walk you through our security architecture and provide documentation for your compliance reviews.
Contact Security Team