Security posture
Enterprise-grade security,
by default.
Built on the controls auditors look for — so your team can ship AI without slowing down legal.
- ISO 27001
- Aligned
- SOC 2
- Aligned
- GDPR
- Compliant
- APPs
- Australian Privacy Act
Encryption
- •All data encrypted in transit via TLS 1.2+
- •Data encrypted at rest using AES-256
- •API keys encrypted with PGP symmetric encryption before storage
- •Passwords hashed using secure one-way algorithms
Access controls
- •Row-level security (RLS) enforced on all 26+ database tables
- •Workspace-based tenant isolation — you cannot access data outside your workspace
- •Role-based access control (admin, builder, runner, viewer)
- •JWT-based authentication with automatic token refresh
Audit & monitoring
- •Comprehensive audit logging for all sensitive operations
- •Immutable audit logs — cannot be modified or deleted via client
- •Shared app access logging with privacy-preserving hashed identifiers
- •Rate limiting on API endpoints to prevent abuse
Infrastructure
- •Hosted on enterprise-grade cloud infrastructure
- •Automatic backups and disaster recovery
- •Edge functions execute in isolated sandboxed environments
- •No customer data used for AI model training
Data privacy
- •IP addresses and user agents are hashed before storage — raw values are never persisted
- •Data minimisation — only essential information is collected
- •You can request data deletion at any time
- •Shared content crawled by search engines is blocked via robots.txt, meta tags, and X-Robots-Tag headers
Compliance alignment
- •ISO 27001 — information security management (Annex A controls for access, cryptography, operations security)
- •SOC 2 — trust service criteria (security, availability, confidentiality)
- •GDPR — consent management, data minimisation, right to erasure, privacy by design
- •Australian Privacy Act / APPs — compliant with Australian Privacy Principles
Sub-processors
The following third-party services process data as part of the Synergaid platform:
| Service | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | United States |
| Google — Gemini family | AI model inference (Gemini 2.5 Pro, 3.1 Pro, 3 Flash, 2.5 Flash, 2.5 Flash Lite, 3 Pro Image) | United States / Global |
| OpenAI — GPT-5 family | AI model inference (GPT-5, GPT-5.2, GPT-5 Mini, GPT-5 Nano) | United States |
| Perplexity | AI-powered research (user-configured) | United States |
| Firecrawl | Web scraping (user-configured) | United States |
Data retention
Account data: Retained while your account is active. Deleted upon request.
App run history: Retained for 12 months after creation.
Shared app access logs: Retained for 90 days, then automatically purged.
Audit logs: Retained for 24 months for compliance purposes.
Incident response
In the event of a security incident, Synergaid will notify affected users within 72 hours in accordance with GDPR and Australian Privacy Act requirements. To report a security concern, please contact us immediately.