End-to-End Encryption
TLS 1.3 in transit and AES-256 at rest for platform data stores and secrets.
Security
TLS 1.3 in transit, AES-256 at rest, SOC 2 Type II, and RBAC on workspace APIs.
TLS 1.3 in transit and AES-256 at rest for platform data stores and secrets.
Annual third-party audits with controls for availability, confidentiality, and processing integrity.
Workspace audit events with export, plus RBAC-gated access to security settings and API keys.
Kong introspects API keys via Identity and forwards signed tenant context to every service.
Privacy-by-design data handling with configurable retention and data subject request workflows.
Owner, Admin, Developer, Operator, Viewer, and Billing Manager roles with scoped API keys and teams.
All customer data is protected using industry-standard encryption:
Our infrastructure is designed with security and reliability in mind:
Application security practices:
Access controls:
Syntra maintains compliance with major regulatory frameworks:
Incident response:
Our team follows strict security protocols:
If you discover a security vulnerability, please report it to our security team immediately:
Email: security@smecloud.app
We appreciate responsible disclosure and will work with you to address any vulnerabilities promptly.
Email security@smecloud.app for questionnaires, pen-test summaries, or DPA requests.