Synthesis Intelligence ← Back to Synthesis
Security

Security Incident Response Policy

Synthesis Intelligence, Inc. · Last updated March 29, 2026

01Purpose

This policy establishes procedures for identifying, responding to, and recovering from security incidents that affect the Synthesis platform, its users, or their data. The goal is to minimize damage, reduce recovery time, and protect merchant and customer data.

02Scope

This policy applies to all systems, data, and services operated by Synthesis Intelligence, Inc., including:

03Incident Classification

SeverityDescriptionResponse Time
CriticalConfirmed data breach, unauthorized access to merchant or customer data, compromised credentialsImmediate (within 1 hour)
HighSuspected breach, unauthorized access attempts, service compromise, malware detectionWithin 4 hours
MediumUnusual access patterns, failed authentication spikes, configuration errors exposing dataWithin 24 hours
LowMinor policy violations, non-sensitive system anomalies, phishing attempts (blocked)Within 72 hours

04Incident Response Phases

Phase 1 — Detection & Identification

Phase 2 — Containment

Phase 3 — Eradication

Phase 4 — Recovery

Phase 5 — Post-Incident Review

05Notification Requirements

Affected Merchants

If merchant or customer data is confirmed to have been compromised, we will notify affected merchants within 72 hours of confirmation, including:

Platform Partners

We will notify Amazon (within 24 hours per SP-API requirements), Shopify, Meta, and other platform partners as required by their partner agreements and data protection requirements. Amazon security incidents are reported to security@amazon.com.

Regulatory Authorities

We will notify relevant regulatory authorities as required by applicable law (e.g., GDPR, CCPA) within mandated timeframes.

06Data Breach Procedures

In the event of a confirmed data breach involving merchant or customer personal data:

  1. Immediately revoke all potentially compromised access tokens (Amazon, Shopify, Meta)
  2. Audit BigQuery access logs to determine the scope of data accessed
  3. Determine which merchants and customers are affected
  4. Prepare breach notification communications
  5. Offer affected merchants assistance in notifying their customers if required

07Roles & Responsibilities

RoleResponsibility
Incident LeadCoordinates response, makes containment decisions, communicates status
EngineeringInvestigates technical root cause, implements containment and fixes
CommunicationsDrafts and sends notifications to merchants, partners, and authorities

08Preventive Measures

09Policy Review

This policy is reviewed and updated at least every 6 months, or immediately following a security incident that reveals gaps in the response process.

10Contact

To report a security incident or vulnerability:

Synthesis Intelligence, Inc. security@synthesisintelligence.ai