Synonym Logo

Trust Center

Transparency, security, and responsible data handling across all our systems. How we engineer for safety and reliability.

1. Security Overview

At Synonym, security is treated as a foundational element. We implement comprehensive security protocols across all our systems and the products we build to ensure technical maturity and reliability.

  • Encrypted Communication: All data in transit is secured via HTTPS / TLS 1.3.
  • Secure Cloud Infrastructure: Enterprise-grade perimeter defenses and routing.
  • Access Control: Strict Role-Based Access Control (RBAC) enforced internally.
  • Secure API Architecture: Authenticated and rate-limited endpoints.
  • Continuous Monitoring: Real-time telemetry and anomaly detection.

2. Data Protection Principles

We handle data ethically and responsibly. We collect only the data required to deliver and improve our services.

  • Data Minimization: We only collect necessary, operational data.
  • Purpose Limitation: Data is used exclusively for defined business reasons.
  • Storage Limitation: No indefinite storage; data is purged when no longer needed.
  • Accuracy: We ensure data is kept accurate and up to date.
  • Confidentiality: Strict confidential handling of all client assets.

3. Infrastructure Security

We build on the shoulders of giants, ensuring your backend systems are resilient, available, and scalable.

  • Cloud Providers: We utilize leading cloud architecture (AWS, Vercel, GCP).
  • Encrypted Storage: Data is encrypted at rest using AES-256.
  • Backup Systems: Automated, immutable backups maintained securely.
  • Redundancy & Failover: Systems designed to prevent single points of failure.
  • Uptime Monitoring: 24/7 real-time uptime and performance tracking.

4. Access Control & Internal Security

Not everyone in our team can access everything. We maintain strict internal discipline regarding systems access.

  • Role-Based Access: Access granted only based on explicit requirements.
  • Limited Employee Access: Strict principle of least privilege.
  • Permission Separation: Hard separation between dev, admin, and client environments.
  • Authentication Systems: Multi-factor authentication (MFA) required globally.
  • Audit Logging: Access and modifications are securely logged.

5. Third-Party Services

We carefully evaluate third-party providers for security and reliability before integrating them into our workflows.

  • Analytics Tools: Privacy-first platforms for understanding performance.
  • Hosting Providers: Enterprise-grade infrastructure partners.
  • AI APIs: Secure, isolated integrations with AI models (e.g., OpenAI).
  • Payment Processors: PCI-DSS compliant gateways like Stripe.
  • Communication: Secure, encrypted internal and client communication tools.

6. Incident Response

We act quickly to minimize impact and restore normal operations in the unlikely event of an anomaly.

  1. Detection and classification of the issue.
  2. Immediate isolation and containment.
  3. Rapid internal investigation.
  4. Deployment of fixes and mitigations.
  5. Complete system restoration and verification.
  6. Thorough post-incident review and process update.

7. Data Handling Summary

We only store data necessary for service delivery and legal compliance.

  • Collected: Essential project details and anonymized analytics.
  • Not Collected: Unnecessary personally identifiable information (PII).
  • Retention: Data is kept for the project lifecycle and mandated legal periods.
  • Deletion: Permanent, secure erasure upon request or expiry.

8. Compliance Overview

We simplify compliance by embedding it directly into our engineering standards.

  • GDPR-Aligned Practices: Transparent data control and processing rights.
  • Global Protection: Adherence to broad data protection principles.
  • Secure Engineering: Security embedded throughout the CI/CD lifecycle.

9. Client Responsibility

Security is a shared effort. We expect our clients to maintain basic security hygiene on their end.

  • Enforcing secure password usage and MFA on handovers.
  • Properly managing internal access to delivered systems.
  • Keeping API credentials and secrets safe.
  • Ensuring lawful and ethical usage of the systems we build.

10. Transparency Statement

"We believe trust is built through transparency, security, and responsible engineering. Every system we design is built with safety, reliability, and privacy in mind."

11. Contact & Security Reporting

For security concerns, vulnerability reports, or general trust inquiries:

Security: security@synonymstudio.com

Support: support@synonymstudio.com