Security & trust
Intelligence you'd be comfortable explaining to your client.
You're the trusted name in your clients' buildings. SynthExec is built to keep it that way: reading through the access you already control, never moving data out of reach, and never holding a credential it doesn't need.
How your data is handled
Data posture01Reads through your connectorsSynthExec uses the scoped access you grant in your PSA and tools. Nothing is touched outside the permissions you set.
02Tenant isolationEach MSP (and each of your clients) is logically separated. One client's data is never visible to another.
03Credentials sealed, not storedConnector tokens are sealed with AES-256-GCM before they touch disk and decrypted only in memory. No encryption key configured, no connection allowed. The system fails closed, never open.
04Automation without handing over keysWhen a workflow runs, the payload carries no credentials, only a single-use, short-lived run token. Credentials are vended one call at a time, only for connectors in the dispatched graph, and revoked the moment the run ends.
05Your clients' data isn't training dataClient data is used to serve your workflows only. They are not used to train foundation models.
06Encrypted in transit and at restAll traffic is TLS-encrypted; stored data is encrypted at rest on managed infrastructure.
Access & controls
AdministrationRoles
Role-based access
Scope your team to the clients they need. Separate who can view from who can manage, with client-level scoping on every role below admin.
Team
Team controls
Only account owners manage users. Guards prevent deleting the last owner or your own account, and seat caps are enforced at creation.
Billing
Billing isolation
Card details never touch our servers. Payments run through Stripe-hosted checkout with signed, verified webhooks.
On the roadmap: SSO/SAML, an exportable audit log, region and retention controls, and human-approval gates for automations. Timeline shared during evaluation.
This page describes SynthExec's security posture. Current certifications, sub-processors and a full data-processing addendum are available from your account team during evaluation.
Bring it to your security review.
We'll share current certifications, sub-processors and a data-processing addendum during evaluation.