SOC 2 Type II
Independently audited
Our security, availability and confidentiality controls are audited over a twelve month observation period. The report is available under NDA.
Legal
We hold other people's money, so security is an operating constraint rather than a feature. These are the controls we run and how to tell us if you find a gap.
Controls
SOC 2 Type II
Our security, availability and confidentiality controls are audited over a twelve month observation period. The report is available under NDA.
In transit and at rest
All traffic uses TLS 1.3. Data at rest is encrypted with AES-256, and keys are managed in a hardware security module with rotation.
Required
Dashboard access requires a second factor. We support hardware keys and authenticator apps, and we do not use SMS for authentication.
Least privilege
Internal access to production is time bound, approved per request, and logged. No engineer holds standing access to customer data.
Maker checker
Payouts above the threshold you set require a second approver, and the approval chain is recorded on the payout itself.
Continuous
We run annual penetration tests with an independent firm and a continuous bug bounty. Findings are triaged within one working day.
Send details to security@syntrapayments.com, including steps to reproduce and anything needed to demonstrate impact. Encrypt your report with our published PGP key if it contains sensitive detail.
We acknowledge every report within one working day and give you a named contact for the duration of the investigation.
Test against the sandbox rather than production wherever possible, and never access, modify or retain data belonging to another customer.
Give us reasonable time to fix an issue before disclosing it publicly. We will agree a disclosure date with you rather than impose one.
We will not pursue legal action against researchers who follow this policy in good faith.
We pay bounties based on severity and quality of the report, and we credit researchers publicly when they want to be named.