Certifications & Compliance Status
We believe security claims should be verifiable. SyncSocial (ABN 25 643 590 265) does not hold SOC 2 Type II or ISO 27001 certification, and we are not currently undergoing an audit for either. We will update this page if that changes.
We do not handle protected health information and SyncSocial is not intended for HIPAA-regulated use.
We handle personal information in accordance with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches scheme. Payment card data is handled entirely by Stripe, a PCI DSS Level 1 service provider — SyncSocial never stores card numbers.
The controls described below are implemented today and can be reviewed on request at hello@syncsocial.com.au.
Encryption & Data Protection
Data at Rest
- • AES-256-GCM encryption for sensitive credentials
- • OAuth tokens encrypted before database storage
- • Encrypted database backups with point-in-time recovery
- • Secure key management with rotating encryption keys
Data in Transit
- • TLS 1.3 encryption for all API communications
- • HTTPS enforced across all endpoints
- • Secure WebSocket connections for real-time features
- • HMAC-signed OAuth state parameters
Access Controls
Authentication
- • Secure email/password authentication
- • JWT-based session management
- • Automatic session expiration and refresh
- • Password hashing with bcrypt
Authorization
- • Role-based access control (RBAC)
- • Separate user roles table to prevent privilege escalation
- • Security definer functions for role verification
- • Team-based permissions with granular controls
Row Level Security
Every database table is protected by Row Level Security policies, ensuring users can only access their own data:
Infrastructure Security
Cloud Infrastructure
- • Hosted on enterprise-grade cloud infrastructure
- • Automatic scaling to handle traffic spikes
- • Geographic redundancy for high availability
- • Regular security patches and updates
API Security
- • JWT token verification on all protected endpoints
- • Rate limiting to prevent abuse
- • Input validation and sanitization
- • XSS protection with DOMPurify
Application Security
Content Safety
- • AI-powered NSFW content filtering
- • Automatic blocking of inappropriate images
- • Content moderation for uploaded media
- • Safe content verification before publishing
Secure Integrations
- • OAuth 2.0 for all social platform connections
- • Encrypted token storage with automatic refresh
- • Minimal scope permissions requested
- • Immediate token deletion on disconnect
Data Handling & Privacy
Data Residency & Hosting
Availability & Transparency
Core services are probed every five minutes from outside our infrastructure. Current availability, response times and 90 days of history are published openly.
View live system status →Incidents that affect publishing are surfaced in-app to affected customers while they are ongoing, not only after the fact.
Security Questions?
If you have security concerns or want to report a vulnerability, please contact us.
hello@syncsocial.app