Skip to main content

We use cookies for essential site functions and anonymous analytics. Choose what to allow.

Accepts all cookies and closes this banner
Reject All
Trust Center

Everything your security team needs — in one place.

HIPAA BAA, GDPR DPA, sub-processors, architecture review, and a security questionnaire. SyncRivo does not currently hold a SOC 2 report.

Mutual NDA where applicable.

Encrypted in Transit
TLS; OAuth tokens encrypted at rest
HIPAA — BAA Available
For Enterprise customers
GDPR — DPA Available
Hosted in the US (Google Cloud us-central1)
Message Content Not Stored
On the normal relay path — only message IDs

The SyncRivo Trust Pack

Four artifacts for your enterprise security review. Request individually, or get the full pack.

HIPAA Business Associate Agreement

BAA available for Enterprise healthcare and life-sciences customers. Signed before any Protected Health Information is processed.

Start BAA Process

GDPR Data Processing Agreement

GDPR Article 28 DPA and sub-processor list available. SyncRivo is hosted in the US on Google Cloud (us-central1).

Request DPA

Security Questionnaire

Responses covering data handling, encryption, access controls, sub-processors and incident response. SyncRivo does not currently hold a SOC 2 report.

Request Questionnaire

Architecture & Data-Flow Review

How a message enters, is transformed, and exits SyncRivo without its content being stored on the normal relay path.

View Architecture

How a message moves through SyncRivo

How message content stays off SyncRivo storage on the normal relay path.

  1. 1
    Webhook in (signed, TLS)

    Source platform sends a signed event. Unsigned or malformed events are rejected before any processing.

  2. 2
    In-memory routing

    Routing rule resolved. The message payload is processed in memory; content is not stored on the normal relay path.

  3. 3
    In-memory transform

    Mentions, threads, attachments, reactions translated to the target platform schema inside the same request.

  4. 4
    Delivery via official API

    Sent over TLS using scoped OAuth 2.0 tokens that are encrypted at rest.

  5. 5
    Activity recorded, no content

    Message IDs are kept so threads, edits and reactions stay in sync, and delivery activity goes to the activity log. The optional retry queue temporarily holds undelivered messages.

Operational Transparency

Status, sub-processors, disclosure, and policy — public, dated, change-logged.

Status Page

Service status overview. Contact support for current incident status.

View

Sub-Processors List

Public list of every sub-processor we use, with location, purpose, and last review date.

View

Vulnerability Disclosure

Coordinated disclosure program. Email security@syncrivo.ai. 24-hour triage.

View

Incident Response Policy

How we detect, triage, and notify. 72-hour notification under GDPR Article 33.

View

Data Retention Policy

What we keep and for how long. Message content is not stored on the normal relay path.

View

Cookie Policy

Cookies we set and why. No third-party advertising trackers on syncrivo.ai.

View

Procurement & Security FAQ

The questions every enterprise security review asks — answered in advance.

No. SyncRivo does not currently hold a SOC 2 report; we provide a security questionnaire and architecture review on request. Our SOC 2 buyer guide explains what a SOC 2 report covers and what to ask any messaging vendor during a security review.
Not on the normal relay path. SyncRivo is a real-time message router, not a message archive. Message content is processed in memory and delivered to the destination platform in real time — messages typically arrive within seconds. SyncRivo keeps only message IDs so threads, edits and reactions stay in sync, and files pass through memory only. If you enable the optional retry queue, undelivered messages are held temporarily until they can be delivered. What SyncRivo does store: routing configuration (which channels are bridged to which), provider OAuth tokens encrypted at rest, message IDs, directory data for synced users, and activity metadata. Data subject access requests, eDiscovery requests and litigation holds for message content are handled at the source platform (Slack, Teams, Google Chat, Zoom, or Webex) where the message is actually retained.
Yes. A Business Associate Agreement (BAA) is available for Enterprise customers handling Protected Health Information (PHI), and the BAA must be executed before any PHI is processed through SyncRivo. Relevant safeguards include TLS in transit, provider OAuth tokens encrypted at rest, message content not stored on the normal relay path, owner/admin/member roles with optional MFA, and an activity log and security event history. Healthcare organizations can bridge clinical Slack or Teams channels with administrative platforms while keeping PHI inside their existing EHR/EMR boundary. Contact sales to start the BAA process.
SyncRivo acts as a data processor under GDPR Article 28, and a Data Processing Agreement (DPA) and sub-processor list are available. SyncRivo is hosted in the US on Google Cloud (us-central1); EU-region hosting is not currently offered. Message content is not stored on the normal relay path, which limits the personal data held in the bridge; directory data (names and emails of synced users) is stored to match people across platforms. Data subject requests can be sent to the Data Protection Officer contact (dpo@syncrivo.ai).
SyncRivo is hosted in the US on Google Cloud (us-central1), using Cloud Run for compute and MongoDB Atlas for configuration storage. The full sub-processor list is published at https://syncrivo.ai/en/sub-processors.
Each platform connection uses OAuth 2.0 tokens scoped to the permissions the bridge needs, which your Slack, Teams, Google, Webex or Zoom admins approve when installing the app. Tokens are encrypted at rest, sent only over TLS, and are not echoed in API responses. Tokens can be revoked at any time from the SyncRivo dashboard or directly from the source platform's app management screen, which disables the bridge.
Each organization's configuration, connections and activity data are scoped to that organization. Cross-organization bridges exist only when both organizations' admins accept a partner connection, and admins can disable a connection at any time. A platform-level organization suspension switch stops all relaying for an organization.
Yes. SyncRivo provides a security questionnaire covering data handling, encryption, access controls, sub-processor management and incident response, plus an architecture review on request. For custom questionnaires from your procurement or security team, contact security@syncrivo.ai.
For confirmed security incidents affecting customer data, SyncRivo notifies affected customers within 72 hours of confirmation, consistent with GDPR Article 33 and the HIPAA Breach Notification Rule timelines. Notifications include the nature of the incident, the categories of affected data, the likely consequences, the measures taken or proposed, and a designated contact for follow-up questions.
Email security@syncrivo.ai with a description of the issue, reproduction steps, and any proof-of-concept materials. SyncRivo operates a coordinated disclosure program with a 90-day embargo for researchers — the researcher agrees not to publicly disclose the vulnerability until either the fix is deployed or 90 days have elapsed, whichever is sooner. Researchers acting in good faith under the disclosure policy are protected from legal action under SyncRivo's safe-harbor language. SyncRivo does not currently operate a paid bug bounty. See the Vulnerability Disclosure Policy for the full terms, scope, and out-of-scope items.

Ready to move past the security questionnaire?

Tell us which artifacts you need. We will send the trust pack and a scoped NDA in one reply.

cookie_consent.banner.aria_announcement