Security & trust

Your data, in your warehouse.

Synopsis doesn't take your data somewhere else. It lands in a warehouse you own, under independently audited controls, with a live trust center where your security review can start today.

Synopsis · trust overview
ItemWhat it meansWhere to verifyStatus
SOC 2 Type IIAudited controlsTrust centerCertified
HIPAAHealth-data safeguardsTrust centerCompliant
Your dataLands in your warehouseQuery it directlyYours
AccessYour team decides who sees whatIn your handsYours
Trust centerPublic, current statustrust.incLive

Ownership, by design

The warehouse is yours — so the data is too.

Most platforms pull your data into their systems and hand you a login. Synopsis works the other way: everything it ingests lands in your own warehouse. You hold the keys, you can query every table directly, and nothing about your business lives only inside someone else's product.

  • You own the account. The warehouse belongs to you, not to Synopsis.
  • Query it directly. Your analysts can run SQL against every table Synopsis builds — no export step, no API gatekeeping.
  • No hostage data. Because the warehouse is yours, your history stays yours.
Your warehouse · SQL console
-- your warehouse, your credentialsSELECT count(*) FROM customers;--> 48,112SELECT count(*) FROM orders;--> 1,904,566-- every table Synopsis builds is queryable by you

Connected as: you · direct access, any time

Access on your terms

Your team controls who sees what.

Not everyone in a company should see everything, and you shouldn't need a support ticket to enforce that. Access to Synopsis is managed by your team: you decide who's in, and what they can reach.

  • You grant access. People get in because your team added them — and lose it the moment you say so.
  • Scoped to the job. Give a team the surfaces they work from without opening up everything else.
  • The direct path stays yours. Underneath it all, warehouse access is governed by you, in your own account.
How data gets in →
Synopsis · access
MemberTeamAccessStatus
A. SerranoFinanceFullActive
J. ParkSales opsDashboards & chatActive
M. AdeyemiSupportData appsInvited
Former contractorNoneRemoved

Audited, in public

SOC 2 Type II, with a live trust center.

Synopsis is SOC 2 Type II certified — an independent auditor examined how our controls operate over time, not just how they look on paper. Our trust center shows current status publicly: certifications, the policies and controls behind them, and every subprocessor we use. For the full audit report and security questionnaire, request access right there — it goes to us, not into a sales queue.

  • SOC 2 Type II. Controls audited in operation, over a sustained period — the stricter form of the standard.
  • HIPAA compliant. Health-data safeguards for the providers and plans that run on Synopsis.
  • Status in the open. Frameworks, policies, and subprocessors are published; full reports are one access request away.
Open the live trust center →
Trust center
ItemTypeReviewed byStatus
SOC 2Type IIIndependent auditorCertified
HIPAASafeguardsAssessedCompliant
Full reportAudit detailRequest accessGated
Status pagePublicAnyone — including youLive

The program behind it

A real security program, not a badge.

Certifications are the output. Underneath them is a working program you can inspect: twenty-five published policies — from risk management and logging to backup, disaster recovery, and secure disposal — and thirty-five controls operating across the company. Even our vendor list is public.

  • 25 policies, published. Risk, physical security, retention, BC/DR, on/off-boarding, remote access — listed in the trust center.
  • 35 operating controls. Access rights, change management, patching, credential management, and more — the things auditors actually test.
  • Subprocessors, named. Every vendor that touches the service is listed publicly, so there are no surprises in procurement.
Review the policies and subprocessors →
Trust center · program
AreaKindWhereStatus
Risk managementPolicyPublishedActive
Logging & auditPolicyPublishedActive
Backup & DRPolicyPublishedActive
Access rightsControlOperatingTested
Patch managementControlOperatingTested
SubprocessorsRegistryPublicListed

The short version

What to tell your security team.

Your warehouse, your data

Everything Synopsis ingests lands in a warehouse you own. You hold the account and the keys.

SOC 2 Type II

Independently audited controls, examined in operation over time — not a self-assessment.

HIPAA compliant

Health-data safeguards assessed and current — see the trust center for status.

A live trust center

Frameworks, 25 policies, 35 controls, and every subprocessor — published at one link. Full reports by access request.

Access your team governs

Your team decides who can use Synopsis and what they see — and can change that decision any time.

Straight answers

Send us your security questionnaire through the trust center — it goes to the team that owns the controls.

Bring your hardest security question.

Start with the trust center, then talk to us. You'll get straight answers — and your data will stay exactly where it belongs: with you.