Skip to content

Trust Centre

Everything a security or procurement reviewer needs, in one place. Each page states its limits as plainly as its controls, because a caveat you find yourself is worth less to us than one we gave you.

Documents

Reporting a vulnerability

Email security@synos.in. We acknowledge within three business days and keep you updated until the issue is resolved. Remediation targets are critical seven days, high thirty, medium ninety, low next scheduled release.

We will not pursue legal action against researchers who report in good faith, act only against their own or authorised environments, and avoid privacy violations, data destruction and service degradation.

The short version

Our default deployment runs inside your perimeter. In an air-gapped or self-hosted install there is no telemetry, no phone-home, and no path for your data to reach us, which also means you can security-test the deployment directly, under your own rules of engagement. That is an option a hosted vendor cannot offer you.

What we do not have, stated here rather than left to be discovered: no SOC 2, no ISO 27001, and no third-party penetration test to date. No MDM or commercial endpoint-detection suite. No 24/7 security operations centre. We are a small firm and these are normal absences at our size; naming them costs us nothing, and being caught inflating one would cost a great deal.

Questionnaires and agreements

We complete security questionnaires and will execute a data processing agreement with standard contractual clauses where one applies. Ask at security@synos.in and we will send the current documentation rather than ask you to wait for a review cycle.