Procurement & due diligence

Procurement Hub

Everything your procurement, legal and IT teams need to evaluate Synap — security, compliance, documentation, company information and answers to the questions that come up most, all in one place.

  • ISO 27001:2022 certified
  • UK GDPR compliant
  • AWS EU / US regions
  • 99.9% uptime SLA
  • UK-based team
  • ICO registered

This hub brings together the security, compliance and legal information teams need to assess Synap. Where the full detail lives elsewhere — our Trust Centre, legal documents or security pages — we link straight to it, so you always land in the right place.

Company information

Legal name
Synap Learning Limited (formerly MyLabs Ltd)
Company type
Private limited company, England & Wales
Company number
08862590
VAT number
GB292133806
Registered office
Castleton Mill, Castleton Close, Leeds, LS12 2DS
Data protection
Registered with the ICO
Team
UK-based — support is not outsourced

Financial standing

Synap is a profitable, privately held company in a net asset position and committed to sustainable growth. Our accounts are prepared annually by a chartered accountancy firm. As a UK limited company, our control and financial information is publicly available on Companies House.

View on Companies House

Security & compliance

Trust CentreISO 27001 report, security policies, resilience and audit evidence.ISO 27001:2022Independently certified — certificate and report in the Trust Centre.GDPR & data protectionHow we meet UK GDPR and protect personal data.Data residencyAWS EU (Ireland) or US (Virginia) hosting options.AccessibilityConformance to WCAG 2.2 AA standards.AI & Responsible AIOur approach to AI and its responsible, secure use.Security overviewProctoring, lockdown, zero-trust access and resilient infrastructure.System statusLive platform status and incident history.

FAQs

Procurement & security questions, answered

Find quick answers or browse our academy.

Still not sure?

Tell us what you need to assess and we will point you to the right answer.

Talk to sales

Or ask an AI about Synap

Synap is hosted on Amazon Web Services (AWS), with production data in EU West (Ireland) by default and US East (Virginia) also available. Our database layer (MongoDB Atlas) runs on AWS in the same region. A small number of ancillary sub-processors (e.g. email delivery, support tooling) are US-based — all listed in our Subprocessors List & Policy.
Yes. Synap runs on AWS in EU West (Ireland) or US East (Virginia). We can also set up additional regions for Enterprise contracts.
We don’t offer self-hosting. Delivering exams, proctoring and analytics with high availability and the ability to scale to thousands of concurrent candidates requires multiple servers and significant network redundancy, so Synap isn’t suited to single-server hosting, and replicating that infrastructure for one customer would be costly. That said, we’re open to private, single-customer AWS or AWS GovCloud deployments for Enterprise contracts, where the additional cost is accounted for.
Yes. Synap is multi-tenant with logical segregation: each customer operates a dedicated portal and all data access is tenant-scoped, so your data is kept separate from other customers’.
Yes. All data is encrypted in transit (HTTPS/TLS) and at rest (AES-256), including backups. Platform passwords are stored only as salted cryptographic hashes, never in plain text.
Encrypted snapshots are taken at least every 12 hours on a rolling schedule, supplemented by continuous point-in-time backup, with additional backups before major changes. Restores are tested regularly. Our recovery objectives are a 30-minute RTO and a 5-minute RPO.
Synap operates to a 99.9% uptime SLA, backed by redundant AWS services deployed across multiple availability zones with real-time monitoring. Live status is published on our status page.
Customer data is deleted at the end of the subscription term, or sooner on your instruction, and personal data is deleted or de-identified once no longer required. Deleted data ages out of backup snapshots on a rolling schedule, within four months at most. Retention is governed by our Data Management Policy and DPA.
Access is limited to Synap team members with a business need — principally engineering and customer support — and, for identifiable data, at your request (for example to investigate an issue or help with training and onboarding). All staff are vetted to ISO 27001 controls and under UK employment law before joining, including a Basic DBS check for access to customer data. We do not outsource support, and administrator access to customer data is logged.
Yes — regularly, by independent, CREST-accredited specialists. Automated external testing runs monthly against the OWASP Top 10 and 17,000+ known attack vectors, with penetration testing at least annually. The latest report is available through our Trust Centre. No major issues have been found; minor findings are reviewed and either addressed or assessed as not applicable.
Synap runs in an isolated AWS VPC with public/private subnet segmentation across multiple availability zones. Edge traffic passes through Amazon CloudFront with AWS WAF filtering and AWS Shield DDoS protection; application services sit in private subnets and reach the database over private VPC endpoints, so database traffic never crosses the public internet. Access uses least-privilege IAM with MFA and SSO, security groups restrict traffic by port and source, and VPC flow logs are enabled. See our Security overview and Trust Centre for detail.
Synap is developed in-house. All production code is peer-reviewed before release, built against the OWASP Top 10 and our ISO 27001-aligned Secure Development Policy, and deployed as immutable images through CI/CD. Third-party dependencies are automatically scanned for known vulnerabilities and kept to a minimum for consistency and reliability.
We run continuous monitoring and alerting with 24/7 emergency response. Incidents are managed under our Incident Response Plan (a redacted copy is in our Trust Centre). For personal data breaches we notify affected customers without undue delay and support your 72-hour UK GDPR obligations.
Yes — Synap holds ISO/IEC 27001:2022 certification, independently certified, covering the development, operation and support of the Synap platform (valid to April 2028). The certificate and audit report are available in our Trust Centre. We don’t hold a SOC 2 report; our ISO 27001 certification serves that role.
Synap is built around UK GDPR and the Data Protection Act 2018, and complies with PECR for electronic communications. We’re an ICO-registered data controller (and processor for customer data). We also support customers operating under other regimes such as the EU GDPR, PIPEDA (Canada) and POPIA (South Africa). Current UK NIS obligations don’t apply to Synap, but we monitor developments including NIS2.
Yes. Our standard Data Processing Agreement incorporates the EU Standard Contractual Clauses and the ICO’s UK International Data Transfer Addendum, and is available in the Documentation section above.
Yes. Under our DPA we assist with Data Protection Impact Assessments and data subject requests — access, erasure and portability — with self-service exports and tools for administrators, and direct support from our team where needed.
Synap does not currently use AI as a core part of the platform, and we do not use your data to train AI models. Any future AI features would be introduced on an opt-in basis and/or governed by specific terms. (Our custom SQE predictive analytics, for example, is a statistical model — not AI or machine learning.)
Synap maintains Cyber Liability (including Cyber Crime), Public Liability, Employers’ Liability and Professional Indemnity (Errors & Omissions) cover, at levels appropriate to our size and industry. As a UK-based employer that doesn’t hire in the US, Workers’ Compensation isn’t applicable. Our policies include worldwide cover, and under UK/EU policies third-party indemnity is included by default (without needing to add Named Insureds). Details and certificates are available on request.
We don’t routinely provide individual customer references — it places an ongoing expectation on our customers, and many, particularly in regulated sectors, now have company-wide policies against giving them. Instead, we publish detailed Customer Stories on our website, and independent, non-incentivised reviews on Capterra, G2, Trustpilot and Software Advice are the best place for candid, independent evaluations of our service.

Anything else?

Need something specific for your assessment?

Security questionnaires, our ISO 27001 report, a signed DPA or anything else your procurement process needs — tell us and we’ll help.

One hub for procurement and due diligence

Everything your procurement, legal and IT teams need to evaluate Synap, in one place.

Certified & independently rated

ISO 27001 Certified