Security & Compliance
Security
Status last reviewed: August 3, 2026
Synaura is in a controlled design-partner preview. This page separates current controls from work in progress so security reviewers can evaluate the deployment without relying on implied certification.
Compliance status
SOC 2 Type I work is in progress. Synaura is not currently SOC 2 certified.
Access control
Application roles, expiring sessions, and organization-scoped data access are implemented. Contracted controls are confirmed during security review.
Connections
Read-only scopes are the default where supported. Exact provider permissions are reviewed during onboarding.
Current deployment status
- Cloudflare Workers and Cloudflare-managed storage provide the application runtime.
- Transport encryption is required for browser and service traffic.
- Capabilities are labeled live, preview, planned, synthetic, or illustrative where relevant.
- A current control matrix and deployment-specific data flow are available during design-partner review.
Plain-language data lifecycle
- Source: Slack, Linear, GitHub, support, and other connected systems remain the systems of record.
- Authorized ingestion: Synaura receives only content allowed by the scopes and locations approved during connection setup.
- Derived context: Synaura may create indexed chunks, relationship metadata, evidence links, and model-derived classifications needed to produce Findings and approved context.
- Retention: Retention windows depend on the deployment and design-partner agreement. The active policy is documented during onboarding.
- Deletion and export: Account-level export and deletion requests are handled through the product or by contacting hello@synaura.ai. Completion timing is confirmed for the contracted deployment.
- Subprocessors: The current hosting, model-processing, and transactional-service list is supplied during security review and updated when the deployment changes.
AI processing
Customer content is processed to provide the requested product behavior. Synaura does not intentionally use customer content to train public or general-purpose models. Provider terms, regions, retention, and model routing are confirmed for the contracted deployment.
Responsible disclosure
Send vulnerability reports to security@synaura.ai. Include reproduction details and a safe contact method. Reports are triaged as quickly as possible.