Your Security is Our Priority
Review the controls SalesSynq has implemented, their limitations, and the assurance work still in progress.
Security Highlights
Implemented safeguards and defense-in-depth controls. No single control is presented as an absolute guarantee.
- TLS 1.2+ in transit (HSTS with a 2-year max-age, includeSubDomains and the preload directive); AES-256-GCM with HMAC-SHA256 for sensitive fields at rest
- Layered tenant controls: scoped queries and authorization checks, plus a repository-return isolation check where tenant context is present
- Append-only audit log with periodic chain sealing; 365-day minimum availability
- CodeQL SAST + OWASP Dependency-Check (CVSS ≥ 7 fails the build) + Gitleaks pre-commit on every change
Compliance Posture
Preliminary legal posture and formal assurance work in progress.
Preliminary legal posture: the service is designed with GDPR, CCPA / CPRA and EU AI Act transparency requirements in mind, but classification and compliance conclusions are pending counsel review. DPIA and ROPA work remains in progress. See our AI Disclosure, the AI Act limited-risk transparency record and Privacy Policy.
In progress: SOC 2 Type 1 readiness program and provider-retention review. An OpenAI Zero-Data-Retention request has been submitted; approval is not claimed.
Planned: Annual third-party penetration test (vendor selection in progress; engagement target before first paying Customer; executive summary available under NDA once delivered).
Not certified: SOC 2, ISO/IEC 27001, HIPAA. We do not claim certifications we have not earned.
Common Security Questions
Quick answers to the most frequent security and compliance questions from our customers.
| Domain | Control Topic | Status |
|---|---|---|
| Access Control | OAuth 2.0 / OIDC SSO with Google and Microsoft; password login disabled by default | Yes |
| Access Control | OIDC SSO carries the Customer’s MFA; native TOTP MFA self-service enrolment in /dashboard/admin/access/security; configurable hard-enforcement for password sign-in | Yes |
| Access Control | Fine-grained authorization via OpenFGA, scoped queries and repository-return isolation checks; strict handling is configuration-dependent | Partial |
| Access Control | Idle session timeout (30 min default); JWT-based session tokens | Yes |
| Web Security | TLS 1.2+ with HSTS (2-year max-age, includeSubDomains and preload directive); browser preload-list inclusion is not claimed; CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy | Yes |
| Web Security | Redis-backed sliding-window rate limiting (10 req/60s on auth endpoints) | Yes |
| Data Protection | Field-level AES-256-GCM with HMAC-SHA256 (RFC 5116); versioned encryption keys | Yes |
| Data Protection | Backups encrypted (Restic), with weekly automated restore drill | Yes |
| Data Protection | Storage-layer encryption-at-rest (always on); optional OS-level LUKS for sovereign deployments | Yes |
| AI Data Handling | SalesSynq does not use Customer Data to train or fine-tune models; enabled-provider handling depends on contract and configuration | Partial |
| AI Data Handling | Common-pattern PII redaction on supported AI paths; additional reasoning redaction policy is configurable and no regex filter guarantees complete removal | Partial |
| AI Data Handling | Primary instrumented orchestration path attaches pseudonymous tenant metadata and requires tenant context; coverage is assessed per provider path | Partial |
| AI Data Handling | Provider-training controls configured where available; OpenAI ZDR request submitted, approval not claimed | In progress |
| Audit & Logging | Append-only audit log with periodic chain sealing; 365-day minimum availability | Yes |
| Audit & Logging | Sensitive request body fields masked in HTTP logs; Sentry PII filtering enabled | Yes |
| Secure Design | CodeQL static analysis on every pull request | Yes |
| Secure Design | OWASP Dependency-Check (fails build at CVSS ≥ 7); Gitleaks secret scanning pre-commit | Yes |
| Privacy | GDPR Article 15–22 data subject request flow with automated retention sweep | Yes |
| Privacy | 72-hour breach notification SLA (GDPR Article 33) | Yes |
| Compliance | EU AI Act — Art. 50 transparency disclosure published; legal classification remains preliminary | In progress |
| Compliance | Preliminary EU AI Act classification record; counsel review and conformity assessment remain open | In progress |
| Compliance | SIG-Lite and CAIQ-Lite questionnaires pre-filled and available under NDA | Yes |
| Compliance | SOC 2 Type 1 attestation | In progress |
| Compliance | Annual third-party penetration test | Planned |
| Compliance | Detailed evidence packets (architecture, control map, sub-processor list, DPA) | By Agreement |
Pre-filled SIG-Lite and CAIQ-Lite questionnaires are available under NDA from [email protected]. Architecture diagrams, the penetration-test executive summary (once delivered), and SOC 2 attestation (once obtained) are released through the same channel.
Need a Security Review Packet?
We support customer security reviews, architecture walkthroughs, and evidence discussions.

