SyndaiSign inStart free

Trust

The answers a security review or a client’s AI-vendor questionnaire usually asks for, in one place. Each one links to the document that binds us.

Your code and data

Every run executes in its own isolated sandbox, destroyed when the run ends, and never reused across customers. Data is encrypted in transit (TLS 1.2+) and at rest. We do not train models on your code, prompts, or output, and we contractually require the LLM providers that execute your work not to train on it either.

Retention

Run artifacts (prompts, diffs, evidence, and logs) are kept while your account is active and deleted when you delete it. Workspace snapshots of a connected repository are kept while it stays connected. Telemetry and error data age out on rolling windows of 90 days to 12 months, and deleted data leaves encrypted backups within a target of 30 days.

Privacy Policy

Subprocessors and models

Every provider that touches customer data, including the LLM providers whose models execute your work, is on our Subprocessor list. We give 30 days’ notice before adding or replacing one.

Subprocessor list

Data Processing Addendum

Our DPA is part of the Terms for every customer, with no signature needed. It covers processor terms, Standard Contractual Clauses for EU, UK, and Swiss transfers, CCPA service-provider terms, 72-hour breach notice, and deletion within 60 days of termination.

Read the DPA

Security reports

Found a vulnerability? Our disclosure policy gives good-faith researchers safe harbor. Email security@syndai.ai.

Vulnerability Disclosure Policy

Certifications

We do not hold a SOC 2 report or ISO 27001 certification today. On request we answer security questionnaires and share our security documentation, as DPA Section 9 describes.

Contact

Privacy and data requests
privacy@syndai.ai
Legal and contracts
legal@syndai.ai
Service status
status.syndai.ai