skip to main content

Syncanix

Trust Center

If your security, privacy, or procurement team is reviewing Syncanix, send them here. We have answered the questions we get asked most, with specifics rather than adjectives. If something you need is missing, email admin@syncanix.com and we will add the answer for the next person who asks.

At a glance

Data region
All stored data lives in the EU (Frankfurt), and so does default AI inference — Claude runs on Amazon Bedrock in-region, under the AWS data-processing terms and never used for training. The non-EU failover provider is disabled by default (EU residency lock).
Encryption
Encrypted at rest; TLS 1.3 in transit. BYOK supported on every plan.
EU AI Act
Syncanix is designed to meet the Article 50 transparency obligations ahead of the 2 Aug 2026 enforcement date, with a counsel-reviewed classification publishing before then. Syncanix provides a limited-risk AI system; the model-level duties sit upstream with the foundation-model providers.
Breach notice
24-hour notification SLA to customers from confirmed breach (DPA Art. 33).
DSAR SLA
24-hour acknowledgement; 30-day fulfilment (GDPR Art. 12).
SOC 2
Not yet certified. Type I evidence collection begins in our first months post-launch; Type II about nine months out.

Where your data flows

Here is exactly what happens to a single message, end to end: what runs where, what we keep, and what is only held for a moment.

  1. Your user writes a message

    TransientEU (Frankfurt)

    The chat widget sends it over TLS to the Syncanix API, where every request is bound to your tenant identity before anything else happens.

  2. Conversation and catalog storage

    StoredEU (Frankfurt)

    The transcript, your capability catalog, and your settings are written to tenant-isolated storage, encrypted at rest.

  3. Documentation retrieval

    TransientEU (Frankfurt)

    When your docs ground an answer, embeddings and reranking run in-region on Amazon Bedrock.

  4. AI reply generation

    TransientEU (Frankfurt)

    Your message and the retrieved context are processed in the EU — Claude runs on Amazon Bedrock in Frankfurt to generate the reply. Nothing is stored at this step, and your content is never used to train a model. If the EU path is ever unavailable, we can fail over to a model provider outside the EU.

  5. The reply streams back

    TransientEU (Frankfurt)

    The answer streams through the Syncanix API to your user’s browser. What persists afterwards is the stored transcript from step 2.

Security

Production runs in the EU (Frankfurt) in a dedicated, fully isolated cloud account. Everything is encrypted at rest and in transit over TLS 1.3. Every workload and database role gets least-privilege access, every API call is authenticated by default, and every customer-facing response carries the usual hardening headers — CSP, HSTS, and X-Frame-Options.

Read the full security overview →

Live system status

A public status page shows the live availability of the API, widget delivery, dashboard and website — refreshed every five minutes, with current incidents and scheduled maintenance windows.

View system status

Security questionnaire

We have filled out the questions that turn up on most vendor reviews — the CAIQ-Lite domains and VSA-Core areas — ahead of time. Each gets an honest yes, partial, or planned, with the detail behind it.

Read the pre-completed questionnaire

Accessibility

We build to WCAG 2.1 AA. The statement lays out where we conform surface by surface, how we get there, and what we know still falls short.

Read the accessibility statement

Subprocessors

Syncanix runs on 7 sub-processors. AWS hosts everything in the EU and runs our default AI inference and document retrieval on Amazon Bedrock, in-region. Anthropic and OpenAI are the model providers we can fail over to outside the EU. Auth0 handles identity, PostHog handles consent-based product analytics, Google Workspace sends our transactional email, and Paddle is our billing provider and merchant of record. Each receives only the data its job requires, and we give 30 days’ notice before any material change — a new sub-processor, a new data category, or a location move.

Read the full subprocessor list →

DPA and cross-border transfers

Our DPA covers the GDPR processor obligations (Article 28), the required security measures (Article 32), and 24-hour breach notification (Article 33). Transfers out of the EEA rely on the EU Standard Contractual Clauses (Module Two), with the UK ICO IDTA addendum and a Swiss FADP rider where they apply. Regional riders cover the UAE, Saudi Arabia, Israel, Egypt, Qatar, Bahrain, Oman, and Jordan.

Read the full DPA brief →

Privacy

We are the processor for the content your users send, and the controller for dashboard accounts. By default we keep conversation data for 30 days, never train foundation models on your data, and keep everything stored in the EU. We honour the GDPR rights — Articles 15, 16, 17, 20, 25, 32, and 33 — and stay out of Article 22 automated decision-making by design: every high-impact action keeps a human in the loop. CCPA and the US state laws are covered by the same superset, alongside the UAE, Saudi, and Israeli regimes.

Read the full privacy notice →

AI compliance

The EU AI Act becomes enforceable on 2 Aug 2026. Syncanix provides a limited-risk AI system, so the Article 50 transparency rules apply to us; the heavier model-level duties under Article 53 sit upstream with Anthropic and OpenAI. The end-user AI disclosure is already live — a clear notice that you are talking to an AI, plus a persistent indicator in the chat header, in all six launch languages. Our formal, counsel-reviewed risk classification is published in full before the enforcement date, alongside the model cards and bias-evaluation methodology.

Read the full AI compliance brief →

Compliance certifications

Here is where each framework actually stands. SOC 2 is on the roadmap, not yet in hand: Type I evidence collection (with Vanta) begins in our first months post-launch, and the Type II report is targeted around nine months out. ISO 27001 follows on the same evidence base. The EU AI Act Article 50 work is verified before 2 Aug 2026. A GDPR DPA and CCPA/CPRA coverage are available today. HIPAA and FedRAMP are deliberately out of scope for v1.

Read the full compliance status →

DSAR — data subject access requests

We acknowledge data subject requests within 24 hours and complete them within 30 days, in line with GDPR Article 12. The five request types map to access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20), and objection (Art. 21).

Submit a DSAR →

Languages

The product, the AI disclosure, and the customer-facing legal notices all ship in our six launch languages: English, Spanish, French, German, Arabic, and Hebrew. Arabic and Hebrew are fully right-to-left, including any icons that carry direction, and a native speaker reviews each release.

Contact