Legal

Security Measures

The controls we run to keep client and company data protected.

Last updated: January 1, 2026

Our Approach

Security is built into every engagement, not bolted on afterward. We operate SOC 2-aligned processes with role-based access, documented controls, and regular internal review across our delivery centers in the US, UK, Canada, and India.

Data Encryption

Client data is encrypted in transit using industry-standard protocols and encrypted at rest within the systems we operate or connect to.

Access Controls

Access to client systems and data is granted on a least-privilege, need-to-know basis and reviewed on a regular cadence. Every specialist working on an account is identified and access is revoked immediately upon offboarding.

Compliance & Certifications

Our processes are aligned to recognized frameworks including SOC 2 and ISO-grade information security controls, with documentation available to clients under NDA during onboarding and audits.

Employee Training

All team members complete security and data-handling training before being assigned to client work, with periodic refreshers and phishing-awareness exercises.

Incident Response

We maintain a documented incident response process, including client notification timelines, so any potential issue is contained and communicated quickly.

Third-Party Vendors

Any third-party tools used in delivery are vetted for security practices before adoption, and data-sharing with vendors is limited to what's necessary for the service being provided.

Reporting a Concern

If you believe you've found a security issue affecting our site or services, please contact info@synexisassist.com and we will respond promptly.