SYNE runs the infrastructure behind climate risk scoring, financial operations and disclosure for enterprises, financial institutions and governments - security here is held to the same standard as the data itself.
The same siloed infrastructure approach we describe on Pricing applies to every customer's data, not just payments.
AES-256 encryption for stored data, TLS 1.3 for data in transit - applied consistently across the platform, not selectively to a subset of "sensitive" fields.
Siloed technology infrastructure for storage, encryption, decryption and transmission - the same architecture we describe for payments applies platform-wide.
Annual third-party penetration testing and ongoing vulnerability scanning, reviewed the same way we'd expect a customer's own security posture to be reviewed.
Role-based access control across every product, with the same audit discipline SYNE Trust applies to a customer's own supplier data.
Every user, whether internal or a customer's own team member, is scoped to the least privilege required for their role - not broad platform-wide access by default.
Every access and change is logged and attributable, supporting the same evidence trail customers rely on for SYNE Trust supplier verification and CSRD-aligned disclosure.
If you've found a security issue affecting SYNE, our Responsible Disclosure process explains how to report it, and what to expect in return - including our commitment not to pursue action against good-faith researchers who follow it.
See our compliance certifications, or talk directly to our security team.