Data isolation & tenancy
In production, each client is provisioned into its own dedicated cloud environment, with
its own databases, storage, encryption keys, service identities and private network. There
is no shared data plane between clients, no cross-client queries, and no path for data to
move between organisations.
Within your environment, divisions and engagements are segregated by signed identity
claims that a user cannot forge, enforced independently at more than one layer.
AI model & data protection
Your organisational data is never used to train AI models. Documents you upload, outputs
you generate and information you process remain exclusively yours; AI processing runs in
your region under terms that contractually exclude training on customer content.
Personal identifiers are automatically detected and replaced with placeholder tokens
before any content reaches an AI model, and restored only inside Synalogic's boundary, so
raw personal data never reaches external AI services. No AI output becomes a finding of
record until a named person has reviewed and approved it; that gate is built into the
platform and cannot be turned off.
Audit trail & logging
Every security-relevant action is written to a tamper-evident audit log with timestamp,
user identity and context. The log is cryptographically chained and can be re-verified to
prove that no record has been altered or removed. Security events are categorised by threat
type and mapped to the ISO 27001 and SOC 2 controls they relate to, retained for at least
thirteen months, and never contain passwords or personal-data payloads.
- Authentication, session and role changes
- Document uploads, access and exports
- AI requests, reviews and approvals
- Configuration and administrative actions
Secure development
Security is built into every stage of the development lifecycle. Every code change passes
automated dependency, container and secret scanning that blocks the build on serious
findings, produces a software bill of materials, and signs the images that reach
production. Services run on minimal hardened images with no shell or operating-system
tooling, rebuilt weekly against patched bases.
- Automated dependency, container and secret scanning on every change
- Software bill of materials and signed production images
- Minimal hardened container images, rebuilt weekly
- Input validation, security headers and strict cross-origin policy
Threat detection & response
Application services are not reachable from the internet; the only path in is through a
managed load balancer and web application firewall that filters malicious traffic,
rate-limits abuse and absorbs denial-of-service. Behind it, real-time security telemetry
classifies threat events and raises alerts, and the platform responds to a range of attack
patterns automatically.
- Real-time threat classification, alerting and escalation
- Continuous infrastructure and application monitoring
- Automatic account lockout on brute-force and anomalous sign-in patterns
- Behavioural detection of bulk export and unusual access
- Every uploaded file malware-scanned before it can be read
Password & credential security
Enterprise-grade password policies enforce strong complexity requirements, password
history and maximum age, and reject passwords built from personal information. Multi-factor
authentication is mandatory for every account, including administrators, and federation to
your corporate identity provider is available.
Sessions are short-lived. Disabling a user ends their access immediately, not at the next
token expiry, and nobody can grant a role higher than their own.
Additional security requirements?
Every organisation has unique security and compliance needs. Where required, we work
directly with your cyber and IT teams to understand whether additional requirements need to
be factored into planning and deployment. Custom configurations, integrations such as
identity federation and log integration with your security operations team, and alignment to
internal frameworks are available and priced as part of the deployment.