Security Statement
Governed by the laws of the State of Wyoming, USA
SyntheStudio LLC is committed to protecting the confidentiality, integrity and availability of customer data. This page summarizes our security program. It is maintained by SyntheStudio and is not an independent certification.
1. Access & authentication
Production systems require strong unique passwords and multi-factor authentication. Access is granted on a least-privilege, need-to-know basis and reviewed regularly. Customer authentication uses bcrypt-hashed credentials, signed session tokens, and supports SSO and OAuth.
2. Encryption
Data is encrypted in transit using TLS 1.2+ and at rest using AES-256 on managed infrastructure provided by our hosting vendors.
3. Hosting & platform
Our applications run on enterprise-grade cloud infrastructure inside US data centers. Vendors are reviewed for their published security posture before being added as subprocessors.
4. Monitoring & logging
We log authentication, administrative and security-relevant events. Logs are retained for incident investigation and reviewed periodically.
5. Backups & disaster recovery
Customer databases are backed up on a regular schedule with point-in-time recovery enabled on supported plans.
6. Incident response
If a security incident affects your data we will notify you in accordance with applicable US state breach notification laws and our contractual obligations.
7. Responsible disclosure
Found a vulnerability? Email security@synthestudio.com. Please give us a reasonable time to remediate before public disclosure. We will not pursue legal action against good-faith researchers who comply with this policy.
Questions about this policy? Email legal@synthestudio.com or visit our contact page. See all legal & policy documents.