Back to Home

Security & Compliance

How we protect your information, and an honest statement of the certifications we do and do not hold.

Last updated: 22 August 2026

AES-256 Encryption
Row Level Security
Encrypted OAuth Tokens
Australian Privacy Act & APPs

Certifications & Compliance Status

We believe security claims should be verifiable. SyncSocial (ABN 25 643 590 265) does not hold SOC 2 Type II or ISO 27001 certification, and we are not currently undergoing an audit for either. We will update this page if that changes.

We do not handle protected health information and SyncSocial is not intended for HIPAA-regulated use.

We handle personal information in accordance with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches scheme. Payment card data is handled entirely by Stripe, a PCI DSS Level 1 service provider — SyncSocial never stores card numbers.

The controls described below are implemented today and can be reviewed on request at hello@syncsocial.com.au.

Encryption & Data Protection

Data at Rest

  • • AES-256-GCM encryption for sensitive credentials
  • • OAuth tokens encrypted before database storage
  • • Encrypted database backups with point-in-time recovery
  • • Secure key management with rotating encryption keys

Data in Transit

  • • TLS 1.3 encryption for all API communications
  • • HTTPS enforced across all endpoints
  • • Secure WebSocket connections for real-time features
  • • HMAC-signed OAuth state parameters

Access Controls

Authentication

  • • Secure email/password authentication
  • • JWT-based session management
  • • Automatic session expiration and refresh
  • • Password hashing with bcrypt

Authorization

  • • Role-based access control (RBAC)
  • • Separate user roles table to prevent privilege escalation
  • • Security definer functions for role verification
  • • Team-based permissions with granular controls

Row Level Security

Every database table is protected by Row Level Security policies, ensuring users can only access their own data:

Brand data isolated per user account
Posts, campaigns, and content scoped to brands
Social platform connections protected per brand
User access restricted to their own brand data
Admin actions logged and auditable
Cross-brand data access prevented at database level

Infrastructure Security

Cloud Infrastructure

  • • Hosted on enterprise-grade cloud infrastructure
  • • Automatic scaling to handle traffic spikes
  • • Geographic redundancy for high availability
  • • Regular security patches and updates

API Security

  • • JWT token verification on all protected endpoints
  • • Rate limiting to prevent abuse
  • • Input validation and sanitization
  • • XSS protection with DOMPurify

Application Security

Content Safety

  • • AI-powered NSFW content filtering
  • • Automatic blocking of inappropriate images
  • • Content moderation for uploaded media
  • • Safe content verification before publishing

Secure Integrations

  • • OAuth 2.0 for all social platform connections
  • • Encrypted token storage with automatic refresh
  • • Minimal scope permissions requested
  • • Immediate token deletion on disconnect

Data Handling & Privacy

Data Minimization:We only collect and store data necessary for the service to function.
No Data Selling:Your data is never sold to third parties. Period.
Data Deletion:Request complete data deletion at any time via account settings or email.
Automatic Cleanup:Temporary scraped content expires automatically after 48 hours.

Data Residency & Hosting

Primary region:All customer data is stored in a single managed Postgres region inside the EU/US commercial hosting footprint. We do not replicate customer data outside that footprint.
Where we operate:SyncSocial is currently offered to businesses in Western markets (UK, EU, US, Canada, Australia and New Zealand). We do not onboard customers in jurisdictions we cannot lawfully serve.
Sub-processors:Hosting and database, email delivery, payment processing, AI model providers and the social platforms you connect. Each is contractually bound to confidentiality and processes data only on our instructions.
Cross-border transfers:Where data reaches a US sub-processor, transfers rely on Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.
Backups & retention:Encrypted point-in-time backups are retained in the same region. Deleted accounts are purged from live systems immediately and from backups on the normal backup rotation.
Regional isolation:Dedicated single-region deployments for enterprise customers with strict residency requirements are available on request.

Availability & Transparency

Core services are probed every five minutes from outside our infrastructure. Current availability, response times and 90 days of history are published openly.

View live system status →

Incidents that affect publishing are surfaced in-app to affected customers while they are ongoing, not only after the fact.

Security Questions?

If you have security concerns or want to report a vulnerability, please contact us.

hello@syncsocial.app