Dieses Dokument liegt nur auf Englisch vor, und die englische Fassung ist die verbindliche. Die Seite drumherum ist in deiner Sprache, der Vertrag nicht. Bei Fragen auf Deutsch schreib an legal@syncek.com.
Sicherheit
Verschlüsselung, Zugriffskontrolle, Backups, Reaktion auf Vorfälle und verantwortungsvolle Offenlegung.
Zuletzt aktualisiert: 26. August 2026
This page describes the technical and organizational measures Syncek has in place to protect Customer Data. It complements, and does not replace, our Privacy Policy and our Data Processing Addendum (DPA), which together define our contractual commitments under the GDPR.
1. Encryption
- In transit. All traffic to Syncek uses TLS 1.2 or higher. HTTP Strict Transport Security (HSTS) is enabled on syncek.com with a two-year max-age and preload; on
api.syncek.comit is one year without preload. - At rest. Production databases and object storage are encrypted at rest with AES-256 or equivalent, managed by the underlying cloud provider.
- Sensitive customer data. API credentials, OAuth tokens, and integration secrets that you entrust to Syncek are additionally encrypted at the application layer using a key-management service, so they are never readable in plain text in our database or backups.
2. Access control
- Role-based access for Syncek personnel with least-privilege defaults. Production access is limited to a small number of named individuals and is revoked on role change or termination.
- Multi-factor authentication is enforced for every administrative account.
- All production access is logged and retained with integrity protections; logs are reviewed during incident response.
- Customer-side authentication uses BetterAuth with hashed passwords (Argon2id) and supports sign-in via Google, Facebook, and GitHub OAuth.
3. Vulnerability management
- Automated dependency and code scanners run on every change, blocking merges that introduce known vulnerabilities.
- Security patches are prioritized by severity and shipped out-of-cycle when needed.
- Dependencies and container images are rebuilt on a regular cadence so that patched versions reach production without waiting for a release.
4. Data residency and transfers
Customer Data is stored in the European Union and United States: primary application hosting and backups stay within those regions. Transfers between them, and to the limited-purpose sub-processors that operate elsewhere (Stripe, Resend, Cloudflare, Google), rely on the EU-US Data Privacy Framework, the EU Standard Contractual Clauses, and supplementary measures. The full list is at our Sub-processors page.
5. Backups and recovery
- Automated daily backups of production data.
- Rolling retention of thirty (30) days, then purged.
- Recovery procedures are documented internally and exercised periodically.
6. Incident response and breach notification
We maintain a written incident-response plan with defined roles and escalation paths. If we become aware of a personal-data breach that is likely to result in a high risk to you, we will notify you within forty-eight (48) hours and every competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours, as required by Arts. 33 and 34 GDPR. Both clocks start on awareness, not on the close of an investigation; a first notification may be preliminary, and we follow it with the remaining detail as we establish it.
7. Network and edge security
Application-level rate limiting protects the authenticated API and the public forms. The edge picture differs by hostname, so this page states it per host: app.syncek.com, the application itself, sits behind Cloudflare, which terminates TLS and provides bot management and DDoS mitigation. syncek.com and api.syncek.com resolve straight to the origin with no CDN or edge layer in front of them.
Strict security headers are applied to responses from the marketing site (Content-Security-Policy, X-Frame-Options, Referrer-Policy, and Permissions-Policy); api.syncek.com carries the first three. Session and authentication cookies are set Secure, HttpOnly and SameSite=Lax. The one exception is the language-preference cookie, which client-side code has to read and so cannot be HttpOnly; it carries no personal data.
8. Compliance status
Syncek is aligned with the GDPR (Regulation (EU) 2016/679), which reaches us under Art. 3(2), and with the US state privacy laws listed in our Privacy Policy. We do not currently hold SOC 2, ISO/IEC 27001, or HIPAA certifications, and we do not accept regulated data that would require them (see the Acceptable Use Policy). The measures on this page are contractual commitments under the Data Processing Addendum, and Annex II there states them in the form a customer can hold us to.
9. Responsible disclosure
Report vulnerabilities to security@syncek.com. We acknowledge valid reports within three (3) business days and keep you informed until the issue is resolved. We do not currently run a paid bounty programme; we do credit reporters who want to be credited.
In scope: syncek.com, app.syncek.com, api.syncek.com, and the Syncek application itself. Out of scope: our vendors' own infrastructure (see the Sub-processors page), findings that require physical access or a compromised end-user device, social engineering of our people or our vendors, and volumetric denial-of-service testing.
Safe harbour. If you follow this policy, we will treat your research as authorized access under our Acceptable Use Policy; we will not bring or support a civil claim against you, we will not refer you to law enforcement, and we will not assert a claim under the Computer Fraud and Abuse Act or the anti-circumvention provisions of the DMCA. If a third party brings action against you for research conducted under this policy, we will say publicly that it was authorized. Following this policy means: act in good faith, do not disrupt the Service, access only the minimum Customer Data needed to demonstrate the issue and delete it afterwards, and give us ninety (90) days from your report before disclosing publicly. If we have not fixed the issue in ninety days, you are free to publish; the clock is a commitment on our side, not a gag.
10. Contact
Vulnerability reports go to security@syncek.com under Section 9. Security questions and requests for additional documentation: legal@syncek.com.