Syntra Logo
Legal & Trust

Security

Last updated: 4 July 2026

Security is central to how we design, build and run Syntra. This page explains, in plain terms, how we protect your data and safeguard the platform - from encryption and access controls to infrastructure security, monitoring, incident response and the responsibilities we share with you.

1.Our approach to security

Security is not a feature we bolt on at the end - it is built into how we design, build and run the Services. Because our AI Agent handles calls, messages and bookings on your behalf, we know it touches some of the most sensitive information your business holds. Protecting that data, and keeping the platform dependable, is fundamental to earning and keeping your trust.

We run a continuous security programme rather than treating security as a one-off project. That means we design systems defensively, review the controls described on this page regularly, and improve them as the platform, the threat landscape and best practice evolve. This page explains, in plain terms, the safeguards we have in place and the responsibilities we share with you.

2.Encryption

We use strong, industry-standard encryption to protect your data both while it moves and while it is stored:

  • In transit - data exchanged with the Services is encrypted using TLS (HTTPS), so information travelling between your browser, your End Users and our systems is protected against interception.
  • At rest - Customer Data stored on our infrastructure, including databases and backups, is encrypted at rest using strong, widely trusted algorithms such as AES-256.

Encryption keys are managed carefully, with access restricted to the systems and personnel that genuinely require it.

3.Infrastructure & hosting

The Services run on reputable cloud infrastructure operated by established providers with strong physical and environmental controls. The underlying data centres benefit from measures such as controlled physical access, surveillance, redundant power and cooling, and independent audits of their operational security.

We host in secure, access-controlled environments and logically segregate Customer Data so that one customer's information is kept separate from another's. Production systems are isolated from development and testing environments, and access to production is tightly restricted and monitored.

4.Access control

We apply the principle of least privilege: our people are granted only the access they need to do their jobs, and no more. Internal access to systems and Customer Data is governed by controls including:

  • Role-based access - permissions are assigned by role and reviewed periodically, and revoked promptly when no longer needed or when someone leaves.
  • Multi-factor authentication - MFA is required for access to sensitive internal systems and administrative tools.
  • Strong authentication - we enforce sound credential practices and use single sign-on where appropriate.
  • Logging & audit - administrative and privileged access is logged, so internal activity can be reviewed and investigated where necessary.

5.Application & network security

We build and operate the Services with security in mind at every stage of development:

  • Secure development - we follow secure coding practices and put changes through code review before they reach production.
  • Dependency & vulnerability scanning - we scan our code and third-party dependencies for known vulnerabilities and address significant issues promptly.
  • Network protection - the platform sits behind firewalls and network controls, with sensitive systems shielded from direct public access.
  • Monitoring - we monitor our systems for anomalies and suspicious activity so we can respond quickly.
  • Periodic testing - we carry out security testing, including periodic penetration testing, to find and fix weaknesses before they can be exploited.

6.Availability & resilience

We want the Services to be there when you and your End Users need them. We take regular, encrypted backups of Customer Data and maintain disaster-recovery practices designed to help us restore service and recover data in the event of a significant failure.

We build on resilient, redundant infrastructure to reduce the impact of individual component failures, and we test and refine our recovery procedures over time. Details of availability commitments, where they apply to your plan, are set out in the relevant agreement.

7.Our people

Security depends on people as much as technology. We work to make sure the individuals behind the Services understand and uphold their responsibilities:

  • Background checks - we carry out appropriate screening of personnel where lawful and relevant to their role.
  • Security training - our team receives security and privacy awareness training so good practice is part of everyday work.
  • Confidentiality - our personnel are bound by confidentiality obligations covering the data they may access.

8.Sub-processors & vendors

To deliver the Services we rely on a limited set of carefully selected sub-processors and vendors - for example for cloud hosting, telephony, messaging and AI models. Before engaging a third party that may handle Customer Data, we assess its security and privacy practices, and we impose contractual data-protection terms requiring it to protect that data and to process it only on our instructions. You can see the sub-processors we use, and how to subscribe to change notifications, on our Sub-processors page.

9.Compliance

We align our practices with recognised industry standards and frameworks, such as SOC 2 and ISO 27001, and we are continually working to mature and, where appropriate, formally validate our security programme against them. We will share verified attestations here and with customers as they become available.

Our handling of personal data - including how we support obligations under laws such as the GDPR and applicable US privacy laws - is described in our Privacy Policy. Where we process personal data in Customer Data on your behalf, we do so under our Data Processing Addendum, which sets out the security and data-protection commitments that apply.

10.Incident response

Despite strong safeguards, no platform can promise that a security incident will never occur. We maintain an incident-response process so that, if something does happen, we can act quickly and responsibly. We monitor for signs of compromise, and when we detect a potential incident we investigate, work to contain and remediate it, and take steps to prevent it recurring.

Where a security incident affects your Customer Data, we will notify you without undue delay in line with our commitments in the Data Processing Addendum and applicable law, and we will provide the information you reasonably need to meet your own obligations.

11.Shared responsibility

Security is a partnership. We work hard to secure the platform, and there are important steps you can take to keep your Account and your End Users' data safe:

  • Use strong, unique credentials - protect your Account with strong passwords and keep them confidential.
  • Enable multi-factor authentication - turn on MFA for your users wherever it is available.
  • Manage user access - grant access only to those who need it, use appropriate roles, and remove access promptly when it is no longer required.
  • Obtain the necessary consents - make sure you have the consents and lawful bases needed to contact your End Users and to process their data through the Services.
  • Report concerns quickly - tell us straight away if you suspect unauthorised access to, or misuse of, your Account.

12.Reporting a vulnerability

We welcome reports from security researchers and customers, and we believe responsible disclosure makes everyone safer. If you believe you have found a security vulnerability or weakness in the Services, please tell us at hello@syntra.ai with enough detail for us to reproduce and investigate the issue.

Please give us a reasonable opportunity to investigate and address the issue before disclosing it publicly, and avoid accessing or modifying data that is not your own, degrading the Services, or affecting other customers while testing. We appreciate your help in keeping Syntra and its customers secure, and we will acknowledge good-faith reports.

The best investment you’ll make this year

Join the 1% of businesses always open, always earning.