Trust · Security overview

Security overview

The questions a security review asks, answered before you ask them, including what each control does not cover.

Reviewed 2 October 2026

11 in place2 partly2 not in place

What we hold

What of our data do you store?

In place

Your Salesforce metadata: object and field names, automation, code, and the relationships between them. Documents you upload. Your account and team records. We do not copy your CRM records, so no contacts, accounts, opportunities or cases.

Where is our data hosted?

In place

In the United States. The application and its database run on servers in Boston, files are kept in a private bucket in eastern North America, and encryption keys are held in Google Cloud in us-east4. Every company involved, and its region, is on the subprocessors page.

What this does not cover: There is no choice of region yet. A European option is planned but not available.

Who can reach it

How do you keep one customer's data from another's?

In place

The database enforces it, not the application. Every tenant-scoped table has a row level security policy, and the policy is forced so it applies even to the account the application connects as. A query that forgets to filter by customer returns nothing rather than everything.

Is that isolation tested, or asserted?

In place

Tested against a real database on every run. The suite creates two customers and proves one cannot read or delete the other's records. A separate check refuses to let those tests be skipped in an environment that claims to verify isolation.

AI

Does our data train a model, or sit in an AI provider's logs?

In place

No training: Anthropic and OpenAI do not train on API traffic. Where it is logged depends on the plan. On Free you bring your own key, so every AI call runs on your account with that provider and never on ours, and the platform has no key of its own to fall back to. On a paid plan with included AI, calls run on SynconAI's accounts with those providers instead.

Credentials

How are our Salesforce and AI credentials stored?

In place

Encrypted with AES-256-GCM under a data key held per customer, and each data key is itself encrypted by a key in Google Cloud KMS that never leaves Google. Each value is bound to its customer and purpose, so it cannot be decrypted after being moved to another customer or column. Credentials are never returned to the browser once saved.

Changes to your org

Can the AI change our Salesforce org on its own?

In place

No. Every change is a proposal that a person approves. Before it is offered, it is validated against your org with a check-only deploy, so the errors you see are real Salesforce errors. Each deploy writes a record of what was asked for, what produced it, who approved it and how to undo it.

Can one person push a change to production alone?

In place

Not while a second admin exists. The person who made a production change cannot approve it; another admin must. Rolling back a production deploy also needs an admin. A workspace with a single admin can approve its own change, and the activity log records that it did.

What can an external AI client connected to our workspace do?

In place

Read only, and only the orgs that token is scoped to. It cannot create, edit or deploy anything. Every call it makes is written to your audit log with the tool it used.

Accountability

Is privileged activity recorded?

Partly

Privileged actions are written to an audit log you can read, including every call made by an external AI client. It covers privileged actions rather than every read.

What this does not cover: Ordinary reads within the application are not individually logged, so this is a record of privileged activity rather than a complete access trail.

Availability

What stops a runaway client or a stolen credential?

In place

Per-route rate limits, keyed to the user or the token rather than only the address, so one customer cannot exhaust another's allowance. Machine-facing endpoints are limited separately from human ones.

Getting your data out

What happens when we disconnect an org or leave?

In place

Disconnecting an org removes the stored copy of its metadata. Records are held per customer with a cascade, so deleting the account removes what belongs to it.

What we do not have

Do you hold SOC 2 or ISO 27001?

Not in place

No. SynconAI 360 holds no security certification. Several alternatives do, and if a certificate is a requirement for your review then we do not meet it today. What exists instead is set out on this page, control by control.

What this does not cover: A SOC 2 Type I engagement has not been signed. There is no date to give, and quoting one before an auditor is engaged would be the kind of claim this page exists to avoid.

Do you have a penetration test report?

Not in place

No independent penetration test has been commissioned, so there is no report to share.

What this does not cover: Security review to date has been internal.

Reporting a problem

How do we report a vulnerability?

Partly

Email security@synconai360.com with what you found and how to reproduce it. We will confirm receipt and tell you what we are doing about it.

What this does not cover: There is no bounty programme and no published response time commitment yet, so this is an address that is read rather than a formal disclosure process.