SSyncPay
Security

Boring, deliberate security.

SyncPay reads financial data for a living, so security isn't a feature — it's the operating condition. Here is how we treat your data, in plain language.

Vault door with shield — security illustration

The short version

We connect with the least privilege that works — read-only wherever the source allows it. We never initiate, hold or route funds. Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Access inside your workspace is role-based, logged and reviewable.

  • Read-only connections; SyncPay cannot move money
  • TLS 1.2+ in transit, AES-256 at rest
  • Role-based access control, per entity
  • Complete audit log of every view and change

Practices we hold ourselves to

Least data. We ingest what reconciliation needs — amounts, references, timestamps, counterparty names. We do not ask for card numbers or credentials to your bank; connections go through the providers' own authorisation flows.

Isolation. Each customer's data lives logically separated, keyed to your workspace. Staff access is exceptional, ticketed and logged; there is no casual "support browsing" of customer ledgers.

Retention on your terms. You choose how long matched history stays. Deleting your workspace deletes the data — actually deletes it, on a stated schedule, not "deactivates" it.

Honest incident handling. If something ever affects your data, you hear it from us first, with specifics and a timeline — not from a status page footnote.

Questions we welcome

Security reviews, questionnaires and data-processing agreements are part of normal onboarding, not an annoyance. Ask us the hard questions — a vendor who handles payment data should expect nothing less.