Synthesis Intelligence ← Back to Synthesis
Security Overview

Security at Synthesis

Synthesis is built on Google Cloud Platform with enterprise-grade security at every layer. Your business data is encrypted, isolated, and accessible only to your authorized team members.

01Encryption

Encryption in Transit
All data transmitted between your browser and Synthesis is encrypted with TLS 1.2+. We enforce HTTPS via HTTP Strict Transport Security (HSTS) with a one-year policy including all subdomains.
Encryption at Rest
All stored data — in Google BigQuery, Firestore, and Cloud Storage — is encrypted at rest using AES-256 encryption, managed by Google Cloud's Key Management Service.

02Authentication

03Access Control

Role-Based Permissions

Every user is assigned a role within their organization. Permissions are enforced server-side on every request — not just in the UI.

RoleCapabilities
ViewerRead-only access to dashboards and insights
MemberRun queries, view data, manage own sessions
AdminInvite team members, manage brand settings, access all analytics
OwnerFull control including billing, brand claiming, and organization settings

Brand-Level Access Control

Users can only access brands they are explicitly authorized for. Brand access is verified on every API call through a two-layer check: an in-token cache for speed, plus a live Firestore verification for accuracy.

04Data Isolation

Your data is never mixed with other customers' data. Every organization receives its own isolated infrastructure:

05API Security

06Rate Limiting & Usage Controls

07Credential Management

08Infrastructure

Google Cloud Run
Serverless hosting with automatic scaling, built-in DDoS protection, and no exposed public IP addresses. Managed by Google's infrastructure security team.
Google BigQuery
Enterprise data warehouse with AES-256 encryption at rest, fine-grained IAM access controls, and automatic audit logging of all queries.
Google Firestore
NoSQL database with automatic encryption, per-document access rules, and real-time audit logging via Google Cloud Audit Logs.
Google Cloud Storage
Object storage with AES-256 encryption, per-object access controls, and versioning for uploaded brand files.

09Audit Logging & Monitoring

10Compliance & Policies

Privacy Policy
Comprehensive privacy policy covering data collection, usage, storage, sharing, and your rights. Read our Privacy Policy
Incident Response Plan
Documented 5-phase incident response protocol with severity classification, 72-hour breach notification, and post-mortem procedures. Read our Incident Response Policy
GDPR Compliance
Mandatory compliance webhooks for customer data requests, customer data deletion, and full shop data erasure. All requests verified via HMAC signatures.
Data Retention
Clear data retention policies. Account data deleted within 30 days of account termination. You can request data deletion at any time.

11Security Summary

CategoryWhat We Do
Encryption (Transit)TLS 1.2+ with HSTS enforcement
Encryption (Rest)AES-256 via Google Cloud KMS
AuthenticationFirebase JWT with automatic token refresh
Authorization4-tier RBAC with per-brand access control
Data IsolationPer-organization BigQuery datasets and storage paths
API ProtectionCORS whitelist, security headers, HMAC webhooks
Input ValidationTyped models, parameterized queries, file type whitelist
CredentialsEnvironment variables + GCP Secret Manager
MonitoringQuery logs, GCP audit logs, usage tracking
CompliancePrivacy policy, incident response plan, GDPR webhooks

12Questions?

If you have questions about our security practices or need additional documentation for your compliance review, contact us at:

Synthesis Intelligence, Inc. security@synthesisintelligence.ai