Trust

Security, privacy, and compliance first — built on Azure with enterprise-grade protection and industry-leading certifications.

Certifications

ISO 27001

Certified

SOC 2 Type II*

In Progress

Microsoft Azure

Powered

* SOC 2 Type II audit currently in progress with a Big Four accounting firm — completion expected September 2026.

Hosting & Isolation

Our practice

Azure Infrastructure

Hosted in Microsoft Azure — enterprise-grade physical and network protection, with all infrastructure defined as code.

Our practice

Organization & Workspace Isolation

Every record is scoped to your organization and workspace. Workspaces compartmentalize teams, departments, or topics.

Our practice

Encryption at Rest & in Transit

All data is encrypted at rest (AES-256) and in transit (TLS 1.2+) — protected at every stage of processing and storage.

Access Control

Your control

Least Privilege

Role-based access control shows users only what they need — permissions follow roles, never defaults.

Your control

Single Sign-On

Your users sign in with SSO through Microsoft Entra ID.

Your control

Explicit Membership

Only members of a workspace can add users to it — access follows explicit membership, never implicit hierarchy.

Our practice

Production Access

Our own access to production is limited to a small set of named officers, under MFA on managed devices, reviewed quarterly.

Data Handling

Our practice

Classification & Minimization

All customer content is handled at the highest sensitivity level by default. We process only what is needed to provide the service and never sell your data.

Your control

Retention & Deletion

You control your data’s lifecycle. On deletion or termination, content is removed within up to 30 days (per backup retention policy).

Our practice

Continuity & Backup

Continuous backup with point-in-time restore, zero-downtime deployments, and availability monitoring keep the service resilient.

AI Governance

Our practice

Inference Only

Your data is used only to serve your request — never to train models. Any provider-side copies are limited to short-lived operational retention of up to 30 days, then deleted.

Your control

Model Control

Your admins control which AI models are available, per model, enforced server-side across chat, workflows, and automations.

Our practice

Sandboxed Execution

AI-generated code runs in an isolated, network-egress-blocked sandbox — each run in its own container.

Sub-processors

Our practice

A Deliberately Small Vendor Surface

The platform is built on Microsoft Azure; AI model and integration providers process data strictly as data processors under data-processing agreements with purpose limitation and no-training commitments.

Our practice

Verified Annually

Every sub-processor is verified annually against a current SOC 2 Type II report or ISO 27001 certification.

Security Operations

Our practice

Continuous Monitoring

Microsoft Defender for Cloud monitors the platform continuously, with security alerts routed to the security officer.

Your control

Audit & Oversight

A complete audit log records every user and admin action — who, what, and when, without conversation content — exportable by your admins anytime, with an events API for your SIEM.

Our practice

Secure Development & Testing

Static analysis and dependency-vulnerability gates block every code change until they pass; an independent penetration test runs annually.

Our practice

People & Assets

Managed, encrypted endpoints, security awareness training, and infrastructure-as-code providing a complete, versioned asset inventory.

Incident Response

Our practice

Documented & Practiced

A documented incident-response runbook with severity classification drives detection, containment, and resolution — work continues until the incident is resolved.

Our practice

Breach Notification

Customers receive written notification within 48 hours of confirmation of any incident affecting their data, including scope, consequences, and corrective measures.

Privacy-First Governance

Governance through transparency, not surveillance

Your control

What Admins Can See

Who uses AI and when, how much is used (usage patterns, costs), and which models and tools are accessed.

Your control

What Remains Private

Chat conversations and prompts, generated reports and documents, and your intellectual property — never exposed, not even to admins.

Our practice

Industry-Standard Model

The same governance model as Microsoft Copilot, ChatGPT Enterprise, and Google Workspace AI.

Responsible Disclosure

Found a vulnerability or have a security concern? We welcome responsible disclosure and respond to every report. Email security@synthgram.ai — or see our machine-readable disclosure policy at /.well-known/security.txt.

Email a security report