Trust Center

Security you can check, not just read about

Live platform status, an honest account of where we stand on ISO 27001 and SOC 2, and the full picture of where your data lives and who touches it. Nothing on this page is a claim we cannot evidence.

Section 1 — Live transparency

Platform status

Read live from our platform health checks every time this page loads, and refreshed once a minute while it stays open.

Operational

All systems operational

Last checked 19:07 UTC

Last 30 days

96.67%

30 days agoToday

Incident record

Confirmed security incidents affecting customer data, since we started operating.

Security incidents
0

Confirmed incidents affecting customer data, all time.

Days since last incident
None recorded

Counted from the most recent confirmed incident.

Mean time to resolve
None recorded

Averaged across resolved incidents. Nothing to average yet.

Availability target
99.50%

Contractual monthly availability target for the platform.

Section 2

Compliance & audit posture

Where we actually stand on each framework — including the ones we have not certified against yet.

Frameworks

Where we stand

Each framework carries the status we can actually evidence today. Alignment means we implement the requirements; certification means an auditor has issued a certificate. We do not blur the two.

  • GDPR

    Data processing agreements, EU-only hosting, documented retention and deletion, and a published privacy policy.

    Aligned

  • NIS2

    Risk management, incident handling and supply-chain security practices aligned to the directive's requirements.

    Aligned

  • ISO 27001

    Our ISMS is documented in draft: scope, risk assessment method, six policies and a Statement of Applicability covering all 93 Annex A controls. Management approval and the first operating records come next. We are not certified yet.

    In progress

    Target: Stage 1 audit — no date is booked until a certification body is appointed

  • SOC 2

    Planned after ISO 27001. No audit has been scoped and no report exists today.

    Planned

    Target: scoping starts after ISO 27001 certification

SypraSam is not currently ISO 27001 certified and holds no SOC 2 attestation. We publish the status of every framework — including the ones still in progress — rather than a wall of badges, because you will find out either way during due diligence.

Certification roadmap

The ISO 27001 path and the phase we are in right now.

  1. Gap assessment

    Measured our existing controls against Annex A in August 2026 and recorded what was missing.

  2. Controls implementation

    Closing the gaps and building the evidence trail an auditor will ask for.

    We are here

  3. Stage 1 audit

    External review of our ISMS documentation and readiness.

  4. Stage 2 audit

    External review of the controls operating in practice.

  5. Certification

    Certificate issued. Until then, this page will not show one.

Progress in this phase

As of 30 September 2026

Done so far

  • ISMS scope decided: the platform and the organisation that runs it
  • Risk assessment method, risk register and risk treatment plan
  • Six information security policies, reviewed by the CTO
  • Statement of Applicability covering all 93 Annex A controls
  • Incident management plan, internal audit and management review programmes, and a corrective-action process
  • First outline of the asset inventory and the legal and privacy register
  • 66 technical controls assessed against the running platform, gaps included

Next, on the way to the Stage 1 audit

  • Management approval of the ISMS documents
  • First access review, incident drill and risk assessment on record
  • Signed NDAs and a recorded security briefing for the whole team
  • First internal audit and management review
  • A certification body appointed and the Stage 1 audit booked

The ISMS documents are drafts until management approves them.

Control matrix

A selection from our draft Statement of Applicability, which covers all 93 ISO 27001:2022 Annex A controls, grouped the way Annex A groups them. Where a control is written down but not yet in operation, the line says so.

Organizational

Annex A.5

  • Security policies

    Six written policies — information security, access control, cryptography, acceptable use, secure development and supplier security — reviewed by the CTO and awaiting management approval.

  • Penetration testing

    No independent penetration test has been performed to date. We plan to commission one.

  • Supplier management

    Our draft supplier policy sets the bar before any supplier joins our register: security terms, a data processing agreement where personal data is involved, and reviewed assurance evidence such as certifications.

  • Incident response

    A written incident management plan sets severity levels, named roles, evidence handling and the GDPR 72-hour notification path. It awaits management approval and its first drill.

  • Access lifecycle

    Our draft access policy calls for access on documented request with least privilege, and for all access to be revoked within 24 hours of someone leaving.

People

Annex A.6

  • Confidentiality obligations

    A bilingual NDA for everyone with access, founders included, is drafted and awaits legal review before it is signed.

Physical

Annex A.7

  • EU data centres

    Physical security is inherited from Hetzner's data centres in Germany (platform) and Finland (backup storage), both in the EU.

Technological

Annex A.8

  • Encryption in transit

    Connections to the platform are TLS-encrypted, and plain HTTP is redirected to HTTPS.

  • Encryption at rest

    Backups are encrypted before they leave the cluster, and the credentials customers store with us are encrypted with AES-256-GCM. Database and storage volumes are not yet encrypted at rest.

  • Network access

    A deny-all firewall guards every node. The Kubernetes API and SSH are not reachable from the internet; operators connect over WireGuard, each with their own key.

  • Role-based access control

    Permissions are granted by role, with least privilege as the default.

  • Tenant isolation

    Each customer runs behind its own namespace, node pool and database boundary.

  • Audit logging

    Security-relevant actions are logged with actor, time and object.

  • High availability & backups

    Three control-plane nodes, a three-member PostgreSQL cluster with synchronous replication and a load balancer; failover is not yet proven in a recorded test. On 29 September 2026 we restored an encrypted production database backup end to end for the first time, which evidences that the restore procedure works — not the recoverability of customer data.

  • Vulnerability management

    Every backend merge request is checked for known vulnerabilities our code can actually reach, and a finding blocks it. Container images are not scanned yet.

  • Signed images

    Every platform image is signed in CI as it is published, and each signature is recorded in the public Rekor transparency log. The cluster verifies signatures and reports unsigned images; rejecting them is the next step.

  • Secrets management

    Credentials live in a managed secret store, never in code or configuration files.

Section 3

Data & architecture transparency

Where your data is hosted, who processes it, how tenants are separated and when it is deleted.

Data residency

All data hosted and processed in the EU

The platform runs in Hetzner data centres in Germany. Customer data is stored and processed inside the European Union, and we make no third-country transfer of it. AI-assisted extraction runs on the customer's own provider account, not ours — that is set out in full below.

Hosting
Hetzner, Germany
Processing
European Union
Third-country transfers
None for platform data

Subprocessors

Every third party that can process data on our behalf, what it is used for, and the safeguard that covers it.

Subprocessors
SubprocessorPurposeProcessing locationTransfer safeguard
Hetzner Online GmbH PlatformInfrastructure and data centre hosting for the platform.Germany (EU)Stays in the EU
Google Ireland Limited This websiteWebsite analytics after consent.Ireland (EU) and United StatesStandard Contractual Clauses

A data processing agreement is in place with every subprocessor listed here. We will notify customers before adding a new subprocessor that processes platform data.

AI providers

AI runs on your provider account, not ours

SypraSAM does not provide an AI system of its own. We run no models, we send no data to a model on our own account, and no AI provider is a subprocessor of ours. AI features work by connecting your organisation's own provider account.

No AI system of our own
We operate no models and use no SypraSAM-held AI vendor account for customer data. That is why no AI provider appears in the subprocessor table above: there is no processing relationship for us to declare.
Your account, your contract
AI features use credentials you supply. The contract with that vendor is yours, the usage is billed to you, and you can revoke the credentials at any time without going through us.
We help you set it up
Configuring a provider is part of onboarding, and our team works through it with you. It is a service we offer, not a task we hand over.
No provider, no AI features
Configure none and the AI features are simply unavailable. Nothing falls back to a SypraSAM-operated model, because we do not run one.

Provider types you can configure

Not our subprocessors
  • Anthropicanthropic
  • OpenAIopenai
  • Google AIgoogleai
  • Microsoft Copilotcopilot

The provider types the platform accepts. Each one you configure is your processor, under your contract — none of them is ours. Setup details, including the endpoint a Microsoft Copilot or Azure deployment needs, are part of onboarding.

What your provider is used for

Document analysis
Reads the documents you supply — this is what the import wizard runs on.
Record extraction
Pulls structured records out of those documents.
Scenario translation
Turns a scenario you describe in plain language into parameters the platform can run.

Each feature can point at a different provider you have configured, and each has its own default.

  • Credentials are encrypted at rest and never handed back in plaintext, and a connection test confirms the setup works without running a real import.

  • A provider you configure belongs to your tenant. Where an instance-wide provider exists, your own provider of the same type takes precedence for your tenant.

Tenant isolation

How one customer's data is kept away from another's. Shown at the level of the model — the specific topology stays private.

Isolation boundaries, outermost first

Your tenant

Dedicated namespace

Dedicated node pool

Separate database

Separate credentials

Another tenant

Separated by the same four boundaries. No shared namespace, node pool, database or credentials.

Dedicated namespace
Workloads run in a namespace of their own, with network policy restricting what may talk to them.
Dedicated node pool
Compute is not shared with other tenants, so noisy neighbours and cross-tenant escape are both off the table.
Separate database
Each tenant has its own database rather than a shared schema with a tenant column.
Separate credentials
Every tenant's services authenticate with their own credentials, scoped to that tenant alone.

Data flow & retention

What we collect, where it goes, how long it stays and what ends it.

  1. Step 1

    Collect

    Data arrives from your connectors, uploads and user activity.

  2. Step 2

    In transit

    Data reaches the platform over TLS-encrypted connections.

  3. Step 3

    Process

    Normalisation and matching build your inventory; AI-assisted extraction adds to it when you have connected your own provider.

  4. Step 4

    Store

    Stored in your own database in the EU; backups are encrypted before they leave the cluster.

  5. Step 5

    Delete

    Removed on your request or on contract end, backups included.

Retention and deletion by data category
Data categoryPurposeRetentionDeletion
Identity dataNames, work email addresses and roles used to attribute licences to people.For the contract termWithin 30 days of contract end or on request
Software & licence dataInstalled software, entitlements, contracts and spend — the inventory itself.For the contract termWithin 30 days of contract end
Usage telemetryWhich applications are actually used, to find unused licences.24 months rollingAutomatically once out of the window
Audit logsSecurity-relevant actions, for your audits and ours.12 monthsAutomatically once out of the window
Support correspondenceTickets and messages exchanged with our team.24 months after closureAutomatically, or on request

On termination, customer data is deleted within 30 days unless a longer statutory retention period applies. Export before deletion is available on request.

Section 4

Proof & engagement

The documents behind the claims, how to report a vulnerability, and what we have shipped recently.

Security package

Request our security pack

One bundle that answers most of a security questionnaire before you have to send one.

  • Security whitepaper — architecture, controls and operational practices in detail.
  • Data processing agreement — our standard DPA including the subprocessor list.
  • SIG / CAIQ responses — the standard questionnaires, pre-filled.
Request the security pack

Sent by email, usually within two business days. We ask for a company address so we know who received which version.

Report a vulnerability

Found something? Tell us before you tell anyone else and we will work it with you. Good-faith research is welcome here.

  • We acknowledge every report within two business days.
  • We will not pursue legal action against good-faith research that follows this policy.
  • We credit reporters who want to be named once the issue is fixed.
  • In scope: our platform and this website. Out of scope: denial of service, social engineering and physical attacks.
Security contact
info@syprasam.org
Machine-readable policy
/.well-known/security.txt

Security changelog

Security-relevant changes we have shipped, newest first.

  1. Consent Mode v2, denied by default

    Privacy

    Analytics signals are denied until a visitor opts in, and no analytics script loads before consent.

  2. Non-production deployments excluded from search

    Hardening

    Staging and preview environments now serve noindex and disallow crawling, so pre-release content cannot be indexed.

  3. Contact endpoint hardened

    Hardening

    Server-side schema validation, per-IP rate limiting and a honeypot field on the public contact form.

Entries are published once the change is live. Automated scan results are labelled as such so you can tell a machine finding from a human claim.