Security

Your business runs on this.
So it is built to be trusted.

One system holding your customers, your money and your people is only worth having if the boundaries are real. Here is exactly where ours are, including the parts that are still under way.

  • GDPRCompliant
  • SOC 2Under way
  • ISO 27001Under way
  • We say "under way" because it is. Neither audit is finished, and we would rather tell you that than let a badge imply otherwise.

What we commit to

Eight promises, and what each one means.

Your data stays yours

We do not sell it, mine it, or train models on it. On a self-hosted deployment the database is yours outright and we never hold your production data at all.

Your own database, in your region

Every customer gets their own isolated data, not a shared table with a filter bolted on. Self-hosted customers run their own project and choose its region themselves.

Encrypted at rest and in transit

TLS 1.3 between your browser and us, AES-256 for anything stored. Applied automatically, with nothing to configure.

Nobody else can see your records

Isolation is enforced by the database itself, not by the screen in front of it. A request that should return nothing returns nothing, whatever the interface asks for.

Every change leaves a trail

Who changed what, and when. Access to production systems is logged, and record history stays with the record.

You choose which AI model runs

Pick the provider per department, or bring your own key. The AI is not a fixed black box you have to accept along with the rest.

The AI asks before it acts

It drafts, suggests and prepares. Anything that changes a record, sends a message or moves money waits for a person to approve it.

Take everything with you, any time

Export your data whenever you want, without asking us and without a retention call. Leaving should cost you nothing but the decision.

How it is enforced

The measures, in writing.

These are not aspirations. Each one is a commitment in our Data Processing Agreement, which is a contract rather than a marketing page.

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Tenant isolation via organisation identifiers and Row-Level Security
  • Least-privilege access controls and authentication for staff
  • Audit logging of access to production systems
  • Regular patching and dependency updates
  • Monitoring for errors and anomalies

Where your data lives

It depends on how you run it.

Self-hosted. You own the database and choose its region. We never hold your production data, and you can revoke our access at any time.

Managed. We run it for you on our infrastructure, and the region is set by the deployment rather than picked from a menu. If you need your data in a specific jurisdiction, self-hosted is the honest answer and we will say so.

Every company that touches data on our behalf is named in the sub-processor list, with its purpose and region. We keep one list rather than a friendlier summary alongside it.

Found something?

Tell us and we will act on it. Report a vulnerability to security@nearsync.ai. We will not take legal action against anyone reporting a genuine issue in good faith.