Trust Center
How we protect your data and your ad accounts
Synter runs autonomous agents against real ad accounts and real budgets. This page is a hub for the policies, sub-processors, internal controls, and live status that back that up — with links to the full detail behind each one.
At a glance
The short version. Full technical detail is on our security architecture page.
Encryption everywhere
OAuth tokens, API keys, and service credentials are encrypted at rest. All traffic runs over TLS. We never store your ad platform passwords.
Workspace isolation
Every customer's data, credentials, and agent activity live in a fully isolated workspace — never visible to another organization.
Hard spend limits
New campaigns always launch paused, and a server-side budget cap is enforced before any platform API call — regardless of instructions.
Complete audit trail
Every action an agent or user takes is logged: timestamp, actor, entity, before/after values, and whether it was allowed, coerced, or blocked.
Internal security controls
Operational practices we run continuously, independent of any single feature or product release.
Access reviews
Repository and infrastructure access is reviewed on a recurring basis, with permission levels tracked per collaborator.
Branch protection & code review
Production branches require passing checks and review before merge; a sample of merged pull requests and their review decisions is retained.
Vulnerability scanning
Dependencies are scanned continuously (automated dependency audits plus Dependabot alerts), with remediation tracked to resolution.
Patch management
Dependency and security patches are tracked and merged on a regular cadence, with records of what shipped and when.
Environment separation
Development, staging, and production run in isolated environments with separate credentials, databases, and deployment pipelines.
Change tracking
Production changes are tied to tracked tickets and sampled release records — code, approval, and release notes — for every deploy.
Sub-processors
We use a small set of vetted vendors to host, secure, and operate the service — for example Vercel and Railway for hosting, Prisma Postgres for our primary database, Clerk for authentication, and Stripe for payments. Every sub-processor and what it's used for is listed on our sub-processors page, kept current as vendors change.
View the full sub-processor list →System status
Live, real-time status for the API, database, MCP server, OAuth connections, and AI agent runtime.
View live system status →Data handling & policies
We do not sell personal data. Data is encrypted at rest and in transit, retained only as long as needed, and deleted or anonymized on account closure per our published retention schedule.
Security review or vendor questionnaire?
Our team responds to security questionnaires, provides custom data processing agreements, and can arrange SSO setup or audit access.
Contact Security Team