Enterprise security

We didn't learn security building a startup.

We learned it securing systems that couldn't afford to fail. That experience is embedded in how Synalogic is architected — a dedicated environment per client in the region your obligations require, encryption with customer-managed keys, personal data masked before any AI processing, and a tamper-evident audit trail.

The Synalogic team brings more than fifteen years across professional services, technology delivery, cyber security, risk and resilience, with direct experience securing government agencies and critical national infrastructure. When we say enterprise-grade security, we mean it in the most literal sense: we have built and protected systems where failure was not an option.

Security isn't a feature we added; it's the foundation everything else is built on. Your work product, your client information and your organisational data are protected to the same standard we applied to the most sensitive environments we have worked in.

How we protect your data

Protection, built into the architecture.

Data residency

We deploy in the region your obligations require. For Australian customers that is Australia: application, databases, storage, backups, log archives and AI processing all run in-country, with no replication outside it. Support is delivered onshore.

Encryption everywhere

All data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 with dedicated customer-managed keys held in a hardware-backed key service and rotated automatically.

Access controls

Multi-tier role-based access so users only see what they need to. Mandatory multi-factor authentication, short-lived sessions with immediate revocation, and a complete audit trail protect every interaction.

Enterprise-grade protection

The controls behind the platform.

Data isolation & tenancy

In production, each client is provisioned into its own dedicated cloud environment, with its own databases, storage, encryption keys, service identities and private network. There is no shared data plane between clients, no cross-client queries, and no path for data to move between organisations.

Within your environment, divisions and engagements are segregated by signed identity claims that a user cannot forge, enforced independently at more than one layer.

AI model & data protection

Your organisational data is never used to train AI models. Documents you upload, outputs you generate and information you process remain exclusively yours; AI processing runs in your region under terms that contractually exclude training on customer content.

Personal identifiers are automatically detected and replaced with placeholder tokens before any content reaches an AI model, and restored only inside Synalogic's boundary, so raw personal data never reaches external AI services. No AI output becomes a finding of record until a named person has reviewed and approved it; that gate is built into the platform and cannot be turned off.

Audit trail & logging

Every security-relevant action is written to a tamper-evident audit log with timestamp, user identity and context. The log is cryptographically chained and can be re-verified to prove that no record has been altered or removed. Security events are categorised by threat type and mapped to the ISO 27001 and SOC 2 controls they relate to, retained for at least thirteen months, and never contain passwords or personal-data payloads.

  • Authentication, session and role changes
  • Document uploads, access and exports
  • AI requests, reviews and approvals
  • Configuration and administrative actions

Secure development

Security is built into every stage of the development lifecycle. Every code change passes automated dependency, container and secret scanning that blocks the build on serious findings, produces a software bill of materials, and signs the images that reach production. Services run on minimal hardened images with no shell or operating-system tooling, rebuilt weekly against patched bases.

  • Automated dependency, container and secret scanning on every change
  • Software bill of materials and signed production images
  • Minimal hardened container images, rebuilt weekly
  • Input validation, security headers and strict cross-origin policy

Threat detection & response

Application services are not reachable from the internet; the only path in is through a managed load balancer and web application firewall that filters malicious traffic, rate-limits abuse and absorbs denial-of-service. Behind it, real-time security telemetry classifies threat events and raises alerts, and the platform responds to a range of attack patterns automatically.

  • Real-time threat classification, alerting and escalation
  • Continuous infrastructure and application monitoring
  • Automatic account lockout on brute-force and anomalous sign-in patterns
  • Behavioural detection of bulk export and unusual access
  • Every uploaded file malware-scanned before it can be read

Password & credential security

Enterprise-grade password policies enforce strong complexity requirements, password history and maximum age, and reject passwords built from personal information. Multi-factor authentication is mandatory for every account, including administrators, and federation to your corporate identity provider is available.

Sessions are short-lived. Disabling a user ends their access immediately, not at the next token expiry, and nobody can grant a role higher than their own.

Additional security requirements?

Every organisation has unique security and compliance needs. Where required, we work directly with your cyber and IT teams to understand whether additional requirements need to be factored into planning and deployment. Custom configurations, integrations such as identity federation and log integration with your security operations team, and alignment to internal frameworks are available and priced as part of the deployment.

Security documentation

What your security team can ask for.

The following can be provided to your security, architecture and procurement teams under NDA during procurement or onboarding.

Security architecture document

Reference architecture, control-by-control detail of how each measure on this page is implemented, data-governance model and the improvement register.

Statement of Applicability

The controlled ISO 27001 document covering every Annex A control, with inclusion justification and the basis for controls inherited from our cloud provider.

Audit & test evidence

Internal audit reports, penetration-test executive summaries and retest letters, as each engagement completes.

Security questionnaire responses

Completed responses to standard security questionnaires. We will also complete your organisation's own questionnaire or risk-assessment tool.

Shared responsibility & data flows

The shared-responsibility model between Synalogic, our cloud provider and your organisation, with data-flow diagrams showing where your data is at every point.

Privacy & data processing

Our privacy policy, and the data processing agreement that governs customer content held in the platform.

Standards

Meeting Australian & international standards.

Synalogic operates an information security management system aligned to ISO/IEC 27001:2022, with controls also mapped to SOC 2 and to ISO/IEC 42001:2023 for AI management, supporting your compliance obligations under Australian privacy law. Independent audit, penetration testing and certification are in progress, and the resulting evidence is available under NDA as each completes.

Privacy Act 1988 (Cth) Australian Privacy Principles Notifiable Data Breaches scheme ISO 27001:2022 aligned SOC 2 aligned ISO 42001:2023 aligned

Questions about security?

We're happy to discuss our security practices in detail with your cyber, architecture and IT teams. Contact us directly or request the security documentation.

To report a security concern about a Synalogic system, email contact@synalogic.com.au.