Security & data protection

Security and data protection, by design

Synap is ISO/IEC 27001:2022 certified, GDPR compliant, and built on hardened, resilient infrastructure. Your data stays yours — never sold, shared, or used to train AI.

Independently verified

  • ISO 27001

    Certified to the 2022 standard

  • GDPR

    Compliant, plus global privacy laws

  • 99.9%

    Uptime SLA

  • EU & US

    Regional AWS hosting

Certifications

Certified, and continuously monitored

Synap holds ISO/IEC 27001:2022 certification for our Information Security Management System, independently audited with annual surveillance audits. We use Vanta to monitor our security controls continuously, not just at audit time.

Certified scope
“The development, operation and support of the delivery of the Synap online assessment platform.”

Request our ISO certificate, penetration test summary, policies and more from the Trust Center.

Data ownership

Your data is yours. Full stop.

You keep full control of your content and candidate data. Synap is a processor acting on your instructions — nothing more.

  • You own everything

    All content and candidate data on your portal belongs to you, and never to Synap.

  • No secondary use

    We never sell or share your data, and we never use it to train AI models.

  • Residency, export & deletion

    Keep data in the EU or US, export it at any time, and request erasure on demand.

Compliance & privacy

Built for global data-protection law

GDPR is our primary framework, and our data-protection practices are designed to meet its equivalents worldwide. For education customers, we support FERPA obligations.

  • GDPR (EU)
  • UK GDPR & DPA 2018
  • CCPA / CPRA (US)
  • PIPEDA (Canada)
  • POPIA (South Africa)
  • LGPD (Brazil)
  • Australian Privacy Principles
  • FERPA (US education)

A Data Processing Agreement is available on request, and we keep a deliberately limited, vetted list of subprocessors.

Infrastructure & resilience

Hardened infrastructure, engineered to stay up

Synap runs on AWS with a security-first architecture and the resilience to handle exam-day peaks.

  • AWS, EU & US regions

    Hosted on Amazon Web Services with regional options in the EU and US.

  • Network isolation & hardened runtimes

    Private VPCs and NAT gateways keep systems off the public internet, on minimal, regularly patched runtimes.

  • Encrypted in transit & at rest

    TLS 1.2+ in transit and AES-256 at rest.

  • 99.9% uptime SLA

    A 99.9% SLA as standard, with automated scaling for high concurrency and enhanced SLAs for critical periods.

  • Backups & redundancy

    Continuous backups with tested restores, across multiple availability zones and regions.

  • 24/7 monitoring & insurance

    Round-the-clock automated monitoring, backed by worldwide business and cyber insurance.

Track live availability on our status page. View status

Security practices

How we build and operate securely

The controls behind the platform. Full detail is available in our Trust Center.

Access

  • Single Sign-On (SAML, OIDC, JWT, ADFS)
  • Enforced MFA and strong password policies
  • Role-based, least-privilege access
  • IP allowlisting and audit logs

Testing & monitoring

  • Independent penetration testing (OWASP Top 10)
  • Continuous vulnerability scanning
  • Prioritised, tracked remediation

Secure development

  • Peer code review
  • Automated dependency and code scanning
  • Least-privilege deployments

People & response

  • Staff security training and background checks
  • Documented incident response and breach notification
  • Responsible disclosure programme

Looking for exam security?

Looking for exam security?

This page covers platform security

Everything here is about how we protect your data and run the platform — infrastructure, compliance, access and resilience.

Visit our Trust Center

Securing individual exams

For the controls that keep a specific exam fair and cheating-free — lockdown, proctoring, randomisation, passcodes and more — see assessment security.

Explore assessment security

Security review

Running a security or procurement review?

Send us your security questionnaire, or book a call and we will walk your IT and compliance teams through our certifications, hosting and controls.

FAQs

Security and data-protection questions, answered

Find quick answers or browse our academy.

Still not sure?

Tell us what you need to assess and we will point you to the right answer.

Talk to sales

Or ask an AI about Synap

Yes. Synap is certified to ISO/IEC 27001:2022 for the development, operation, support and delivery of the Synap online assessment platform. Our ISMS is independently audited with annual surveillance audits, and we monitor controls continuously with Vanta. You can request our certificate from the Trust Center.
Yes. GDPR is our primary data-protection framework, and our practices are designed to meet equivalent laws including UK GDPR & DPA 2018, CCPA/CPRA, PIPEDA, POPIA, LGPD and the Australian Privacy Principles. We can provide a Data Processing Agreement (DPA) on request.
No. You retain full ownership of your content and candidate data. We never sell or share it, and we do not use it to train AI models. We act only as a processor delivering the service to you.
Synap is hosted on Amazon Web Services with regional options in the EU and US, so you can keep data in the region that meets your requirements. Internal systems sit inside private VPCs, isolated from the public internet.
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, so it is protected both while moving and while stored.
We deliberately keep our list of third-party subprocessors small and vetted. The current list, and how we manage them, is published in our subprocessor policy.
Yes. We run regular independent penetration tests against the OWASP Top 10 and many other attack vectors, alongside continuous vulnerability scanning. A summary is available from the Trust Center.
A 99.9% uptime SLA as standard, with multi-region redundancy, continuous backups, automated scaling for high concurrency and 24/7 monitoring. Enhanced SLAs are available for critical exam periods, and live availability is on our status page.
We maintain a documented incident-response plan with clear breach-notification commitments, and a responsible-disclosure channel for security researchers to report issues.

Confidence for your security and compliance teams

Book a security review, or explore our Trust Center for certifications, policies and controls.

Certified & independently rated