Skip to main content

Security

Defense in depth across the Synaptis platform.

How we encrypt, authenticate, isolate, and monitor every layer of the system that runs AXIFI and partner deployments.

Last reviewed:

Architecture posture

Synaptis runs on a hardened multi-tenant architecture deployed across HIPAA-eligible cloud regions. Every tenant boundary is enforced at the data, key, and audit layers — not just in the application.

  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Per-tenant data isolation with per-tenant encryption keys via cloud KMS
  • No cross-tenant model training, ever — contractually and architecturally enforced
  • Zero-trust internal network; service-to-service auth via mTLS

Control families

Identity & access

  • SSO via Okta, Azure AD, Auth0
  • Role-based access (RBAC) at every API boundary
  • Just-in-time admin access via approved break-glass workflow
  • Quarterly access review

Application security

  • Static analysis on every PR
  • Dependency scanning + auto-patching for critical CVEs
  • Authenticated penetration testing annually
  • Bug bounty: security@ disclosure with 90-day reply SLA

Infrastructure

  • Defense-in-depth network policies
  • Centralized secrets management
  • Immutable infrastructure (no SSH to prod)
  • Regional failover + tested disaster recovery

Security attestations

  • SOC 2 Type II

    Audit in progress — target Q4 2026

    Synaptis platform + AXIFI

    We are in active SOC 2 Type II engagement with a recognized auditor. Type I report available on request under NDA; Type II expected Q4 2026.

  • Penetration testing

    2026 test complete

    External + internal black-box + grey-box

    Annual third-party penetration test against the Synaptis platform. Latest executed Q1 2026. Summary report available on request under NDA.

    Request pen-test summary
  • Bug bounty

    Active disclosure program

    All public-facing surfaces

    Disclose at security@synaptisusa.com. 90-day reply SLA. Safe-harbor terms documented in the security packet.

Reporting a security issue

Email security@synaptisusa.com. PGP key available on request. We acknowledge all reports within 3 business days and provide status updates every 7 days until resolution. Safe-harbor disclosure terms are documented in our security packet.