Security at Synoro
Enterprise-grade security
Synoro is implementing a formal security and compliance program in preparation for an independent SOC 2 examination. Layered controls, tenant isolation, and auditable AI workflows protect your clients' data and your firm's operations.
Security program in place
No model training on your data
Full tenant isolation
Every AI action logged & auditable
Encrypted at rest & in transit
AI PRIVACY
Automation that stays accountable, isolated, and inspectable.
INFRASTRUCTURE
Encryption, tenant isolation, and MFA for sensitive finance workflows.
OPERATIONAL READINESS
Testing, response, backups, and documentation for security review and diligence.
AI Privacy
Your data is used to serve your business — not to train someone else's model.
No third-party model training
Your data is never used to train external or third-party AI models. Your firm's own approved corrections build your private memory — used only for your books, never shared.
Full data isolation
Strict tenant separation across every customer.
Traceable AI
Every agent action is logged and auditable.
No selling or sharing
Company and client data is never shared with third parties.
Data deletion
Remove your data at any point.
Transparent by design
AI steps show sources, changes, and rationale.
Secure by design
No credential storage
We never store your credentials. Access via revocable tokens only.
Encrypted at rest
AES-256 and HMAC across all stored data.
Encrypted in transit
HTTPS/TLS on every connection.
Security operations
Vulnerability management
Documented triage process and dependency scanning. Independent pentesting is planned; it is not claimed as complete.
Incident response
Documented severity levels, security contact, and notification templates. Tabletop exercises are part of the program.
Backups
Production data is hosted on providers that offer backup capabilities. Restore testing is part of the security program.
Reviewing Synoro for your finance stack?
Questions about security or data processing: security@synoro.ai. Trust center: /trust.