Trust Center

How we protect your data and your ad accounts

Synter runs autonomous agents against real ad accounts and real budgets. This page is a hub for the policies, sub-processors, internal controls, and live status that back that up — with links to the full detail behind each one.

At a glance

The short version. Full technical detail is on our security architecture page.

Encryption everywhere

OAuth tokens, API keys, and service credentials are encrypted at rest. All traffic runs over TLS. We never store your ad platform passwords.

Workspace isolation

Every customer's data, credentials, and agent activity live in a fully isolated workspace — never visible to another organization.

Hard spend limits

New campaigns always launch paused, and a server-side budget cap is enforced before any platform API call — regardless of instructions.

Complete audit trail

Every action an agent or user takes is logged: timestamp, actor, entity, before/after values, and whether it was allowed, coerced, or blocked.

Internal security controls

Operational practices we run continuously, independent of any single feature or product release.

Access reviews

Repository and infrastructure access is reviewed on a recurring basis, with permission levels tracked per collaborator.

Branch protection & code review

Production branches require passing checks and review before merge; a sample of merged pull requests and their review decisions is retained.

Vulnerability scanning

Dependencies are scanned continuously (automated dependency audits plus Dependabot alerts), with remediation tracked to resolution.

Patch management

Dependency and security patches are tracked and merged on a regular cadence, with records of what shipped and when.

Environment separation

Development, staging, and production run in isolated environments with separate credentials, databases, and deployment pipelines.

Change tracking

Production changes are tied to tracked tickets and sampled release records — code, approval, and release notes — for every deploy.

Sub-processors

We use a small set of vetted vendors to host, secure, and operate the service — for example Vercel and Railway for hosting, Prisma Postgres for our primary database, Clerk for authentication, and Stripe for payments. Every sub-processor and what it's used for is listed on our sub-processors page, kept current as vendors change.

View the full sub-processor list →

System status

Live, real-time status for the API, database, MCP server, OAuth connections, and AI agent runtime.

View live system status →

Data handling & policies

We do not sell personal data. Data is encrypted at rest and in transit, retained only as long as needed, and deleted or anonymized on account closure per our published retention schedule.

Security review or vendor questionnaire?

Our team responds to security questionnaires, provides custom data processing agreements, and can arrange SSO setup or audit access.

Contact Security Team