SyncPay reads financial data for a living, so security isn't a feature — it's the operating condition. Here is how we treat your data, in plain language.
We connect with the least privilege that works — read-only wherever the source allows it. We never initiate, hold or route funds. Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Access inside your workspace is role-based, logged and reviewable.
Least data. We ingest what reconciliation needs — amounts, references, timestamps, counterparty names. We do not ask for card numbers or credentials to your bank; connections go through the providers' own authorisation flows.
Isolation. Each customer's data lives logically separated, keyed to your workspace. Staff access is exceptional, ticketed and logged; there is no casual "support browsing" of customer ledgers.
Retention on your terms. You choose how long matched history stays. Deleting your workspace deletes the data — actually deletes it, on a stated schedule, not "deactivates" it.
Honest incident handling. If something ever affects your data, you hear it from us first, with specifics and a timeline — not from a status page footnote.
Security reviews, questionnaires and data-processing agreements are part of normal onboarding, not an annoyance. Ask us the hard questions — a vendor who handles payment data should expect nothing less.