Everything your security team needs — in one place.
HIPAA BAA, GDPR DPA, sub-processors, architecture review, and a security questionnaire. SyncRivo does not currently hold a SOC 2 report.
Mutual NDA where applicable.
The SyncRivo Trust Pack
Four artifacts for your enterprise security review. Request individually, or get the full pack.
HIPAA Business Associate Agreement
BAA available for Enterprise healthcare and life-sciences customers. Signed before any Protected Health Information is processed.
Start BAA ProcessGDPR Data Processing Agreement
GDPR Article 28 DPA and sub-processor list available. SyncRivo is hosted in the US on Google Cloud (us-central1).
Request DPASecurity Questionnaire
Responses covering data handling, encryption, access controls, sub-processors and incident response. SyncRivo does not currently hold a SOC 2 report.
Request QuestionnaireArchitecture & Data-Flow Review
How a message enters, is transformed, and exits SyncRivo without its content being stored on the normal relay path.
View ArchitectureHow a message moves through SyncRivo
How message content stays off SyncRivo storage on the normal relay path.
- 1Webhook in (signed, TLS)
Source platform sends a signed event. Unsigned or malformed events are rejected before any processing.
- 2In-memory routing
Routing rule resolved. The message payload is processed in memory; content is not stored on the normal relay path.
- 3In-memory transform
Mentions, threads, attachments, reactions translated to the target platform schema inside the same request.
- 4Delivery via official API
Sent over TLS using scoped OAuth 2.0 tokens that are encrypted at rest.
- 5Activity recorded, no content
Message IDs are kept so threads, edits and reactions stay in sync, and delivery activity goes to the activity log. The optional retry queue temporarily holds undelivered messages.
Operational Transparency
Status, sub-processors, disclosure, and policy — public, dated, change-logged.
Sub-Processors List
Public list of every sub-processor we use, with location, purpose, and last review date.
ViewVulnerability Disclosure
Coordinated disclosure program. Email security@syncrivo.ai. 24-hour triage.
ViewIncident Response Policy
How we detect, triage, and notify. 72-hour notification under GDPR Article 33.
ViewData Retention Policy
What we keep and for how long. Message content is not stored on the normal relay path.
ViewCompliance Detail Pages
For each framework, a dedicated page explaining what it covers and where SyncRivo stands.
Procurement & Security FAQ
The questions every enterprise security review asks — answered in advance.
Ready to move past the security questionnaire?
Tell us which artifacts you need. We will send the trust pack and a scoped NDA in one reply.