Security at Syntheia

Syntheia’s has adopted stringent security policies and controls that are compliant with ISO 27001 and SOC 2. Our team monitors compliance with these controls, and prove our security and compliance to third party auditors.

If you would like a copy of our attestion and certification relating to security, please feel free to contact us.

Secure Personnel

All Syntheia employees and contractors undergo background checks and sign confidentiality agreements before gaining access to sensitive systems or data. We reinforce this with ongoing security training against current and emerging threats.

Secure Development

Our development lifecycle embeds security by design. New products and major changes undergo security-focused design review, and developers receive annual secure coding training. All development follows OWASP Top 10 standards for web application security.

Secure Testing

We conduct regular third-party penetration testing and vulnerability scanning across all production and internet-facing systems. New systems are scanned before deployment, and major changes undergo testing by both internal security engineers and external specialists. Static and dynamic application security testing, including of open-source components, is built into our development process.

Cloud Security

Our cloud platform delivers complete customer isolation within a secure, multi-tenant architecture, built on the physical and network security of our cloud providers. Data is encrypted at rest and in transit, continuously monitored by dedicated engineers, and protected in line with SOC 2 standards. Access is governed by role-based controls and the principle of least privilege, reviewed and revoked as needed.

Compliance

Syntheia holds independent certifications that validate our security practices, giving customers assurance that their data is protected to the highest standard as we help manage billions of digital identities worldwide.