Security & trust
Your data, in your warehouse.
Synopsis doesn't take your data somewhere else. It lands in a warehouse you own, under independently audited controls, with a live trust center where your security review can start today.
Ownership, by design
The warehouse is yours — so the data is too.
Most platforms pull your data into their systems and hand you a login. Synopsis works the other way: everything it ingests lands in your own warehouse. You hold the keys, you can query every table directly, and nothing about your business lives only inside someone else's product.
- You own the account. The warehouse belongs to you, not to Synopsis.
- Query it directly. Your analysts can run SQL against every table Synopsis builds — no export step, no API gatekeeping.
- No hostage data. Because the warehouse is yours, your history stays yours.
-- your warehouse, your credentialsSELECT count(*) FROM customers;--> 48,112SELECT count(*) FROM orders;--> 1,904,566-- every table Synopsis builds is queryable by youConnected as: you · direct access, any time
Access on your terms
Your team controls who sees what.
Not everyone in a company should see everything, and you shouldn't need a support ticket to enforce that. Access to Synopsis is managed by your team: you decide who's in, and what they can reach.
- You grant access. People get in because your team added them — and lose it the moment you say so.
- Scoped to the job. Give a team the surfaces they work from without opening up everything else.
- The direct path stays yours. Underneath it all, warehouse access is governed by you, in your own account.
Audited, in public
SOC 2 Type II, with a live trust center.
Synopsis is SOC 2 Type II certified — an independent auditor examined how our controls operate over time, not just how they look on paper. Our trust center shows current status publicly: certifications, the policies and controls behind them, and every subprocessor we use. For the full audit report and security questionnaire, request access right there — it goes to us, not into a sales queue.
- SOC 2 Type II. Controls audited in operation, over a sustained period — the stricter form of the standard.
- HIPAA compliant. Health-data safeguards for the providers and plans that run on Synopsis.
- Status in the open. Frameworks, policies, and subprocessors are published; full reports are one access request away.
The program behind it
A real security program, not a badge.
Certifications are the output. Underneath them is a working program you can inspect: twenty-five published policies — from risk management and logging to backup, disaster recovery, and secure disposal — and thirty-five controls operating across the company. Even our vendor list is public.
- 25 policies, published. Risk, physical security, retention, BC/DR, on/off-boarding, remote access — listed in the trust center.
- 35 operating controls. Access rights, change management, patching, credential management, and more — the things auditors actually test.
- Subprocessors, named. Every vendor that touches the service is listed publicly, so there are no surprises in procurement.
The short version
What to tell your security team.
Your warehouse, your data
Everything Synopsis ingests lands in a warehouse you own. You hold the account and the keys.
SOC 2 Type II
Independently audited controls, examined in operation over time — not a self-assessment.
HIPAA compliant
Health-data safeguards assessed and current — see the trust center for status.
A live trust center
Frameworks, 25 policies, 35 controls, and every subprocessor — published at one link. Full reports by access request.
Access your team governs
Your team decides who can use Synopsis and what they see — and can change that decision any time.
Straight answers
Send us your security questionnaire through the trust center — it goes to the team that owns the controls.
Bring your hardest security question.
Start with the trust center, then talk to us. You'll get straight answers — and your data will stay exactly where it belongs: with you.