New Multi-conversation CEO chat with live tool calls, org chart, and Claude MCP control plane shipped in September. See the changelog →
Home/Product/Security
Security & governance

Built like you'd want a company holding your keys to be built.

Synapse holds provider keys so agents can work, and treats them as the high-value secrets they are. Below is what is actually in place — and, where it matters, what isn't yet.

Credentials

Envelope encryption

Every key is sealed with a per-business AES-256 data key, itself encrypted by a master key held in a separate, self-hosted vault (Infisical). A database breach yields ciphertext.

Isolation

Row-level security, enforced at boot

Per-company isolation is enforced in the database. The API checks the policy on startup and refuses to boot if it is not enforced.

Identity

Keycloak SSO, server-side login

OIDC with Google sign-in. Access tokens live in memory, never in URLs; silent refresh; 30-minute inactivity logout; tokens bound to the API they were issued for.

Least privilege

One key, one task

Each agent receives only the credential its task needs — never a global key. Credentials are never written to logs, error messages or the knowledge base.

Edge

CSP, HSTS, CSRF, rate limits

Strict per-request CSP and HSTS. CSRF protection and IDOR test suites across the API. Founder task text is fenced before it reaches GitLab.

Audit

Append-only, on every write

Tasks, wiki edits, CRM records, CEO actions and credential use are recorded with timestamp, actor and purpose.

Agent safety

Agents that can't hurt you by accident.

  • Never push to main. Work arrives as merge requests.
  • Sensitive paths always need a human — auth, secrets, payments, migrations, access control, dependency manifests.
  • QA and Security are read-only agents. They report; they don't patch.
  • Per-company containers, non-root, no Docker socket.
  • Your Claude credential never touches the platform — the team is authorised through a paste-a-code relay.
  • The MCP server holds no credential and cannot approve anything.
Merge gate · !12cto-accept-mr
  • pipelinegreen
  • QA-GATEPASS · 2781 tests
  • SECURITY-GATEPASS
  • pathsbilling/ → HELD for founder
  • auto-mergedeclined · human review required
Governance

Authority is a document.

The CEO's limits are written down, readable over MCP (ceo_authority_get) and editable only in the cabinet. A proposal above the line is queued, and a queued proposal has not happened.

Approve.propose.Pause.override.Revoke.
What we don't claim

Honest boundaries.

Are you GDPR / HIPAA / PCI / SOC 2 certified?
No. Synapse ships a compliance-check framework that runs technical control checks for GDPR, PCI DSS v4.0, HIPAA and SOC 2 against live state (Scale tier). It is not a certification, an attestation or a defence. You remain responsible for your own compliance posture; under the DPA you are the controller and Catalation the processor.
Where do backups live?
Backups are taken and verified. Off-host copies are on the roadmap and not yet in place. We say this here because you'd rather know.
Are the legal documents final?
Terms of Service, Acceptable Use Policy, DPA and Privacy Policy exist as draft v0.1 and are pending counsel review.
Has a third party audited the platform?
Not yet. Every merge passes internal QA and Security gates, and we keep a public changelog of security fixes. An external assessment is planned before the Enterprise tier is sold.

Questions? Ask us directly.

Security questionnaires, architecture reviews, DPA — email and a human answers.