■ Security

Your Data
Stays Yours

Synchronise operates on a principle of minimal access. We read what we need, process it ephemerally, and never store document contents.

Read-only Access

Synchronise requests minimal OAuth scopes. We never modify, create, or delete anything in your connected tools. Your Jira tickets, Notion pages, and Slack messages remain untouched.

  • No write access to any connected platform
  • Revoke access instantly from your settings

Encryption

All data is encrypted in transit using TLS 1.3. OAuth tokens are encrypted at rest using AES-256-GCM before storage in our database.

  • TLS 1.3 for all data in transit
  • AES-256-GCM for tokens at rest

Ephemeral Processing

Document contents are processed in memory and immediately discarded after analysis. We store only metadata (titles, IDs, timestamps) and the findings we generate.

  • No document content storage
  • Findings reference documents, don't contain them

No AI Training

Your data is never used to train AI models. We use Anthropic's Claude API with zero data retention enabled. No cross-customer learning.

  • Zero data retention with AI provider
  • Your insights never shared with other customers
■ Compliance

Enterprise-Ready Security

SOC 2 Type II

Our infrastructure and processes are audited annually for security, availability, and confidentiality.

GDPR Compliant

Full compliance with EU data protection regulations. Standard Contractual Clauses available for international transfers.

Data Residency

Choose where your data is processed. US and EU regions available.

Incident Response

72-hour breach notification. Documented incident response procedures.

■ Sub-processors

Our Technology Partners

ProviderPurposeLocation
VercelHosting & CDNUS, EU
SupabaseDatabase & AuthUS, EU
AnthropicAI ProcessingUS

We notify customers of sub-processor changes with at least 30 days' notice.

Questions about security?

We're happy to answer questions or provide additional documentation for your security review.