Trust
The answers a security review or a client’s AI-vendor questionnaire usually asks for, in one place. Each one links to the document that binds us.
Your code and data
Every run executes in its own isolated sandbox, destroyed when the run ends, and never reused across customers. Data is encrypted in transit (TLS 1.2+) and at rest. We do not train models on your code, prompts, or output, and we contractually require the LLM providers that execute your work not to train on it either.
Retention
Run artifacts (prompts, diffs, evidence, and logs) are kept while your account is active and deleted when you delete it. Workspace snapshots of a connected repository are kept while it stays connected. Telemetry and error data age out on rolling windows of 90 days to 12 months, and deleted data leaves encrypted backups within a target of 30 days.
Privacy PolicySubprocessors and models
Every provider that touches customer data, including the LLM providers whose models execute your work, is on our Subprocessor list. We give 30 days’ notice before adding or replacing one.
Subprocessor listData Processing Addendum
Our DPA is part of the Terms for every customer, with no signature needed. It covers processor terms, Standard Contractual Clauses for EU, UK, and Swiss transfers, CCPA service-provider terms, 72-hour breach notice, and deletion within 60 days of termination.
Read the DPASecurity reports
Found a vulnerability? Our disclosure policy gives good-faith researchers safe harbor. Email security@syndai.ai.
Vulnerability Disclosure PolicyCertifications
We do not hold a SOC 2 report or ISO 27001 certification today. On request we answer security questionnaires and share our security documentation, as DPA Section 9 describes.
Contact
- Support
- support@syndai.ai
- Privacy and data requests
- privacy@syndai.ai
- Security
- security@syndai.ai
- Legal and contracts
- legal@syndai.ai
- Service status
- status.syndai.ai