Trust Center
Security and compliance at Synx Data Labs.
We're building SynxDB Cloud to enterprise standards. This page is our public source of truth for compliance posture, policies, and the vendors we rely on.
Frameworks
Where we stand today.
SOC 2 Type 1 is our immediate target ahead of the SynxDB Cloud GA on AWS. Nothing on this page is marked as certified until an auditor has attested it.
-
SOC 2 Type 1
In ProgressAudit scoped for Security + Availability. Target attestation June 2026.
-
SOC 2 Type 2
Observation startingObservation window opens on completion of Type 1.
-
ISO 27001
In ProgressInformation Security Management System controls being implemented.
-
GDPR / CCPA
PlannedData subject rights and regional data handling on the roadmap; not yet in scope for V1.
Policies
Documented and maintained.
Our information security program is managed in Drata. Customers and prospects can request full policy documents with an NDA in place, contact us for access.
- Information Security Policy
- Access Control Policy
- Incident Response Policy
- Vendor Management Policy
- Business Continuity Policy
- Acceptable Use Policy
- Data Classification Policy
- Risk Assessment Policy
Sub-processors
Who we rely on.
The services below process or store data on our behalf as part of running Synx Data Labs and SynxDB Cloud. We keep this list current and will notify customers at least 30 days before adding a new sub-processor that handles their personal information.
| Vendor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services | Cloud infrastructure, storage, managed services | Customer data, access and infrastructure logs | United States | SCC where applicable |
| Omnistrate | Managed control plane for SynxDB Cloud | Deployment and control-plane metadata | United States | SCC where applicable |
| Cloudflare | DNS, CDN, and Pages hosting for synxdata.com | Visitor IP, request metadata | Global edge network | SCC where applicable |
| Cloudsmith | Package distribution for SynxDB CE | Download logs (IP, user-agent) | European Union (Cork, Ireland) | Inside the EU |
| Drata | Compliance automation and evidence collection | Compliance evidence, employee and vendor records | United States | SCC where applicable |
| Justworks | HR, payroll, employee onboarding | Employee PII (payroll, HR records) | United States | Domestic only |
| Google Workspace | Email, collaboration, document storage | Internal communications and documents | United States | SCC where applicable |
| GitHub | Source control and code review | Source code; limited PII in commit metadata | United States | SCC where applicable |
| 1Password | Credential and secrets management | Encrypted credentials and secrets | United States, Canada | SCC where applicable |
| HubSpot | Lead capture and customer communication | Contact info (name, email, company, role) | United States | SCC where applicable |
Data retention
How long we keep it.
Retention periods below are defaults, reviewed periodically against applicable law. We retain personal information only as long as we have a lawful basis to do so.
| Data category | Retention |
|---|---|
| Account / contact info from signup forms | Active relationship + 3 years; deletion on request |
| Product usage telemetry | 12 months rolling |
| Support / ticket records | Active relationship + 7 years |
| Billing records (once paid customers exist) | 7 years (US tax requirements) |
| Marketing consent records | While subscribed + 3 years after unsubscribe |
| Server / access logs | 90 days |
Spin up a warehouse. Run a query. See for yourself.
Early access is open. A starter cluster is free while we're in preview, no credit card, no sales call.