Security
Last updated: August 18, 2026
SyndTrack handles sensitive financial data, and we take that responsibility seriously. This page describes the security controls we have in place today, the third-party services we rely on, and how you can reach us with security questions.
AES-256 + TLS
Encrypted at rest and in transit
Row-Level Security
Postgres RLS isolates every account
Audit Logging
Key account actions recorded with actor and timestamp
Zero Data Selling
We never sell, rent, or trade your data
Current Security Controls
- Encryption in transit and at rest — Customer data is encrypted in transit (TLS) and at rest (AES-256).
- Authentication via Clerk — Authentication is handled by Clerk, supporting email/password, OAuth providers, and multi-factor authentication.
- Payments via Stripe — Payments are processed by Stripe. We never store credit card numbers or bank account details on our servers.
- Record-level access controls — Postgres row-level security scopes every query to the signed-in account; a deal you share with teammates is visible to those invited members.
Subprocessors
We use the following third-party services to operate the platform:
Core service list as of August 18, 2026. We update this subprocessor list and note the change in our public changelog before a new subprocessor receives customer data. Material changes are also communicated through the account or contact information we have.
| Provider | Purpose |
|---|---|
| Supabase | Database hosting (PostgreSQL) |
| Clerk | Authentication & identity |
| Stripe | Payment processing |
| Vercel | Application hosting & CDN |
| Anthropic | Document parsing and deal scoring (Claude model) |
| Resend | Outbound transactional email; inbound document processing is implemented and signature-verified, but it is not enabled until an inbound domain is configured |
| Sentry | Error and performance monitoring |
| Upstash | Rate limiting, idempotency keys, and webhook deduplication |
| Integrations — transmit account data only after you connect and authorize them | |
| Plaid | Bank transaction import, when the integration is enabled and you connect it |
| Google (Drive / Gmail) | Drive and Gmail import, only after you connect and authorize the integration |
| Microsoft (Outlook / OneDrive) | Outlook and OneDrive import, only after you connect and authorize the integration |
| Dropbox | File import, only after you connect and authorize the integration |
| Carta / CrowdStreet | Sponsor-portal adapters, only when the adapter is configured and you connect it |
Data Retention & Deletion
We retain your data for as long as your account is active. When you close your account through Settings with the required typed confirmation, billing is cancelled immediately and your profile is anonymised. Your portfolio records, transactions, uploaded documents, and generated exports are kept for at least 30 days so support can reverse a mistaken closure. Full erasure of those records is carried out on request rather than automatically: send a request through the in-app help form and we complete it within 30 days of that request. Audit, legal and consent, compliance, billing-notice, and webhook records are deliberately retained. Data shared into a workspace stays with that workspace; closing-user identifiers on those shared rows are redacted when the erasure is carried out.
You can export your portfolio data at any time from your account settings. Contact support through the in-app help form if you need to reverse a mistaken closure during the 30-day retention window.
Uptime and service levels
SyndTrack does not publish a contractual uptime guarantee, and we do not offer billing credits for downtime today. We run the platform on managed infrastructure (Vercel and Supabase) and treat availability as a priority, but we are not going to promise a number we do not yet measure or account for.
Live per-subsystem health (app, Supabase, Stripe, Resend,Anthropic, Upstash) and response latency are published at /status. If you need a contractual SLA for an institutional mandate, contact us via our help page and we will tell you honestly whether we can meet it.
Backup, recovery, and uptime
- Managed backups of the production database are handled by Supabase under our current plan. We do not publish a recovery window, because point-in-time recovery is not confirmed enabled on the production project.
- Recovery objectives: we do not commit to a contractual recovery point or recovery time objective today. Restores have not been rehearsed against production at a measured target, so publishing one would be a guess.
- Data residency: production database hosted in a U.S. region (AWS us-east-1 via Supabase). Application and CDN delivery run on Vercel's global edge. Subprocessors, including Anthropic, may process information in the United States and other regions under their contractual and security commitments; we do not promise that all processing occurs exclusively in the United States.
- Status & uptime: live status at /status with per-subsystem health (app, Supabase, Stripe, Resend,Anthropic, Upstash) and response latency.
Compliance roadmap
SyndTrack does not currently hold SOC 2 attestation, and we have not yet booked a SOC 2 audit or a third-party penetration test. We would rather say that plainly than publish a certification timeline we have not committed to. When an engagement is signed, the dates will appear here.
Controls we operate today
These are the controls we run today, mapped informally to the SOC 2 Common Criteria a reviewer usually asks about. No auditor has verified this mapping.
- CC6.1 Logical access: MFA-capable authentication via Clerk, role-based authorization, Postgres RLS for record-level isolation.
- CC6.7 Encryption: AES-256 at rest, TLS 1.2+ in transit, key management via the cloud provider (Supabase / Vercel).
- CC7.2 System monitoring: Sentry for error tracking, Vercel and Supabase logs, and on-demand subsystem probes at /status. Scheduled health and deliverability jobs run daily, not continuously.
- CC7.3 Incident response: Documented runbooks (incident response, secrets rotation, email deliverability) and a public status page. We are founder-operated and do not staff a round-the-clock on-call rotation: incidents are handled by the founder on a best-effort basis.
- CC8.1 Change management: All production changes ship via reviewed PRs with CI-gated tests. Audit logging records key account and portfolio actions with actor and timestamp; it does not cover every database write.
- A1.2 Backup & recovery: See "Backup, recovery, and uptime" section above.
Working through a vendor questionnaire? Reach us via our help page.
Responsible Disclosure Policy
We welcome reports from security researchers and take every submission seriously. If you believe you have found a vulnerability in SyndTrack, please report it to us privately before any public disclosure so we have a chance to fix it.
How to report
- Send us a private report via our help page with a description of the issue, steps to reproduce, and any proof-of-concept material. Machine-readable contact info is also published at /.well-known/security.txt per RFC 9116.
- Please give us a reasonable time to respond and remediate before any public disclosure. We aim to acknowledge reports within two business days and provide a status update within seven.
- Do not access or modify data that does not belong to you, run automated scanners against production without coordinating with us first, or perform any denial-of-service testing.
Scope
- In scope:
www.syndtrack.ioand any publicly reachable API underwww.syndtrack.io/api. - Out of scope: third-party services we depend on (Clerk, Stripe, Supabase, Vercel, Anthropic, Resend, Sentry, Upstash), social engineering of our staff, and physical attacks. Please report those directly to the respective vendors.
Safe harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy. If you are unsure whether a planned test falls within scope, ask us first via our help page and we will confirm.
Security Contact
Security questions, vulnerability reports, or data requests can be sent via our help page.