Privacy & Security
Security Policy
Technical architecture, encryption standards, SOC2 readiness, and risk management practices.
Last Updated: July 26, 2026
Security Policy
Effective Date: July 26, 2026
1. Data Encryption Standards
- In Transit: All HTTP traffic is strictly encrypted using TLS 1.3 with HTTP Strict Transport Security (HSTS) enforced.
- At Rest: Enterprise databases, storage buckets, and memory vector indices are encrypted using AES-256 with key rotation.
2. Access Control & RBAC
Synaps implements zero-trust authorization. Access to enterprise organization data is restricted via Role-Based Access Control (RBAC) and scoped JWT claim validation.
3. Network & Infrastructure Security
- Multi-tenant data segregation enforced at application and database layers.
- Automated vulnerability scanning for dependencies and container images.
- Rate limiting and WAF rules to protect against OWASP Top 10 vulnerabilities.
4. Incident Response Plan
In the event of a confirmed security incident affecting customer data, Synaps will notify affected enterprise administrators within 72 hours in compliance with GDPR and global breach notification standards.
Security Team Contact: novaecosystems@gmail.com.