Security at Syncendio

1. Our approach

Syncendio handles business-critical data — inventory, purchasing, and sales records — so security isn't optional. This page summarizes how we protect that data in plain language. For the full internal policy, including our incident response plan and breach notification commitments, see our Data Security & Breach Notification Policy, available on request.

2. Encryption

All traffic between your browser and Syncendio is encrypted in transit via HTTPS/TLS. [Confirm and describe encryption-at-rest once the hosting/database provider is finalized — most managed database and storage services encrypt at rest by default; verify and state that here.]

3. Payment security

All subscription payments are processed by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of certification in the payments industry. Card numbers are sent directly to Stripe and never touch Syncendio's own servers, which significantly limits our exposure to payment-card risk.

4. Access controls

Access to production systems and customer data is limited to personnel who need it to do their jobs (least-privilege access). [Describe your actual controls once implemented — e.g., unique logins per team member, multi-factor authentication (MFA) required for admin access, periodic access reviews.]

5. Infrastructure & hosting

[Hosting provider and architecture not yet finalized — fill in once decided (e.g., cloud provider, regions, network isolation, firewall/WAF usage). Note any compliance certifications the provider itself holds, e.g. SOC 2 Type II, ISO 27001.]

6. Backups & availability

[Describe backup frequency, retention, and disaster-recovery approach once the database/hosting stack is chosen and backup jobs are configured.]

7. Vulnerability management

[Describe your patching cadence, dependency/vulnerability scanning, and whether you run periodic penetration testing once these processes are in place.]

8. Incident response

We maintain an internal incident response plan covering detection, containment, investigation, and notification for security incidents. Where a security incident affects personal data, we follow applicable legal notification requirements, including the GDPR's 72-hour supervisory-authority notification rule where relevant and applicable U.S. state breach-notification laws. See our Data Security & Breach Notification Policy for the full procedure.

9. Subprocessors

We use a limited set of third-party providers ("subprocessors") to operate the Service:

We review subprocessors for appropriate security practices before onboarding them.

10. Report a security issue

If you believe you've found a security vulnerability in Syncendio, please report it to security@syncendio.com. We ask that you give us a reasonable opportunity to investigate and address any issue before public disclosure, and that you avoid accessing or modifying data that isn't yours during testing.