Security, privacy, and compliance first — built on Azure with enterprise-grade protection and industry-leading certifications.
Certified
In Progress
Powered
* SOC 2 Type II audit currently in progress with a Big Four accounting firm — completion expected September 2026.
Hosted in Microsoft Azure — enterprise-grade physical and network protection, with all infrastructure defined as code.
Every record is scoped to your organization and workspace. Workspaces compartmentalize teams, departments, or topics.
All data is encrypted at rest (AES-256) and in transit (TLS 1.2+) — protected at every stage of processing and storage.
Role-based access control shows users only what they need — permissions follow roles, never defaults.
Your users sign in with SSO through Microsoft Entra ID.
Only members of a workspace can add users to it — access follows explicit membership, never implicit hierarchy.
Our own access to production is limited to a small set of named officers, under MFA on managed devices, reviewed quarterly.
All customer content is handled at the highest sensitivity level by default. We process only what is needed to provide the service and never sell your data.
You control your data’s lifecycle. On deletion or termination, content is removed within up to 30 days (per backup retention policy).
Continuous backup with point-in-time restore, zero-downtime deployments, and availability monitoring keep the service resilient.
Your data is used only to serve your request — never to train models. Any provider-side copies are limited to short-lived operational retention of up to 30 days, then deleted.
Your admins control which AI models are available, per model, enforced server-side across chat, workflows, and automations.
AI-generated code runs in an isolated, network-egress-blocked sandbox — each run in its own container.
The platform is built on Microsoft Azure; AI model and integration providers process data strictly as data processors under data-processing agreements with purpose limitation and no-training commitments.
Every sub-processor is verified annually against a current SOC 2 Type II report or ISO 27001 certification.
Microsoft Defender for Cloud monitors the platform continuously, with security alerts routed to the security officer.
A complete audit log records every user and admin action — who, what, and when, without conversation content — exportable by your admins anytime, with an events API for your SIEM.
Static analysis and dependency-vulnerability gates block every code change until they pass; an independent penetration test runs annually.
Managed, encrypted endpoints, security awareness training, and infrastructure-as-code providing a complete, versioned asset inventory.
A documented incident-response runbook with severity classification drives detection, containment, and resolution — work continues until the incident is resolved.
Customers receive written notification within 48 hours of confirmation of any incident affecting their data, including scope, consequences, and corrective measures.
Governance through transparency, not surveillance
Who uses AI and when, how much is used (usage patterns, costs), and which models and tools are accessed.
Chat conversations and prompts, generated reports and documents, and your intellectual property — never exposed, not even to admins.
The same governance model as Microsoft Copilot, ChatGPT Enterprise, and Google Workspace AI.
Found a vulnerability or have a security concern? We welcome responsible disclosure and respond to every report. Email security@synthgram.ai — or see our machine-readable disclosure policy at /.well-known/security.txt.
Email a security report