Skip to main content

Enterprise-grade security,
by default.

Built on the controls auditors look for — so your team can ship AI without slowing down legal.

ISO 27001
Aligned
SOC 2
Aligned
GDPR
Compliant
APPs
Australian Privacy Act

Encryption

  • All data encrypted in transit via TLS 1.2+
  • Data encrypted at rest using AES-256
  • API keys encrypted with PGP symmetric encryption before storage
  • Passwords hashed using secure one-way algorithms

Access controls

  • Row-level security (RLS) enforced on all 26+ database tables
  • Workspace-based tenant isolation — you cannot access data outside your workspace
  • Role-based access control (admin, builder, runner, viewer)
  • JWT-based authentication with automatic token refresh

Audit & monitoring

  • Comprehensive audit logging for all sensitive operations
  • Immutable audit logs — cannot be modified or deleted via client
  • Shared app access logging with privacy-preserving hashed identifiers
  • Rate limiting on API endpoints to prevent abuse

Infrastructure

  • Hosted on enterprise-grade cloud infrastructure
  • Automatic backups and disaster recovery
  • Edge functions execute in isolated sandboxed environments
  • No customer data used for AI model training

Data privacy

  • IP addresses and user agents are hashed before storage — raw values are never persisted
  • Data minimisation — only essential information is collected
  • You can request data deletion at any time
  • Shared content crawled by search engines is blocked via robots.txt, meta tags, and X-Robots-Tag headers

Compliance alignment

  • ISO 27001 — information security management (Annex A controls for access, cryptography, operations security)
  • SOC 2 — trust service criteria (security, availability, confidentiality)
  • GDPR — consent management, data minimisation, right to erasure, privacy by design
  • Australian Privacy Act / APPs — compliant with Australian Privacy Principles

Sub-processors

The following third-party services process data as part of the Synergaid platform:

ServicePurposeLocation
StripePayment processingUnited States
Google — Gemini familyAI model inference (Gemini 2.5 Pro, 3.1 Pro, 3 Flash, 2.5 Flash, 2.5 Flash Lite, 3 Pro Image)United States / Global
OpenAI — GPT-5 familyAI model inference (GPT-5, GPT-5.2, GPT-5 Mini, GPT-5 Nano)United States
PerplexityAI-powered research (user-configured)United States
FirecrawlWeb scraping (user-configured)United States

Data retention

Account data: Retained while your account is active. Deleted upon request.

App run history: Retained for 12 months after creation.

Shared app access logs: Retained for 90 days, then automatically purged.

Audit logs: Retained for 24 months for compliance purposes.

Incident response

In the event of a security incident, Synergaid will notify affected users within 72 hours in accordance with GDPR and Australian Privacy Act requirements. To report a security concern, please contact us immediately.