SYNC

Security & access

Data isolation, data privacy, segregation of duties, and a full audit trail

The things a controller, an auditor, or a security-conscious buyer actually asks about — described as what the system does, not a compliance badge we haven't earned.

33
Integrated modules
Multi-wing
P&L by business unit
One login
Finance, HR & Operations
Real-time
Cash & people visibility

Segregation of duties

One permission for the action, a different one for undoing it

Finance access" or "HR access" isn't one flag here — around fifty separate permissions decide exactly how far each person's access goes, granted per business wing. A few of the splits that actually exist in the product today:

Processing a payroll run

≠ Reversing one that's already paid

Two separate permissions — someone can run payroll every month without ever being able to unwind one.

Recording a bank transaction

≠ Deleting or reversing one

Same split across every money-movement module — banks, credit card, petty cash, travel, perks.

Viewing a client record

≠ Editing, deleting, or merging one

View access never implies write access — a directory anyone can browse, not everyone can change.

Marking an employee as left

≠ Resetting their portal login password

An HR lead can offboard someone without ever touching login credentials — that stays admin-only.

Audit trail

Every reversal and deletion leaves a record

Undoing something — a bank transaction, a payroll run, a client record — is exactly where "who did this and why" matters most. Sync logs it automatically, in the same database transaction as the change itself, so an audit entry can never exist without the change it describes, or vice versa.

It covers reversing a bank, credit card, petty cash, or travel payment, deleting a payroll run, a trip, or a client record, marking a resource as left or reactivating them, and any other action gated behind a sensitive, individually-grantable permission. Admins can look up the full history for any record.

Who made the change — the actual user, not just "the system"
When it happened, down to the second
What the record said immediately before the change
What it says now, after
A reason, where the action itself has one — a reversed payment, an offboarded employee

Data & privacy

How your data is actually handled

No certification is claimed here — none is held. This is a plain description of what the product and the Privacy Policy actually commit to.

You control your data; we process it on your instruction

For your own account, Sync is the data controller. For everything you enter about your employees, clients or vendors, your organization is the controller and Sync acts only as a processor — we handle that data to run the Service, under your instructions, not our own.

Access, export or delete — on request

You can request access to, correction of, export of, or deletion of personal data at any time. Every financial and HR report exports to PDF or CSV on demand, so your records were never locked into the product in the first place.

We don't sell data, and we don't use ad-tech

No tracking or advertising cookies, no data brokers, no sharing with third parties for their own marketing. Data goes to Stripe (billing), our transactional email and hosting providers, and — only if you use Ask Sync — our AI provider, which receives just the organization data needed to answer that one question and never uses it to train their models.

Passwords are hashed, sessions are protected

Passwords are stored as a bcrypt hash, never in plain text. Login is rate-limited, and two-factor authentication is available on every account.

A defined retention policy, not indefinite storage

Data is retained while your account is active. Cancel, and it's kept only long enough for you to reactivate or export it, then deleted from active systems — or sooner, on request.

Built for more than one company

Your books stay yours

The business next door could be on Sync too. That's not something you have to take our word on — separation isn't a setting someone can misconfigure, it's how every query is written. Inside your own organization, segregation of duties works the same way: who can act, who can reverse it, and a logged trail of both.

  • Your data is filtered by organization at the query itself — not hidden in the interface
  • That scope is read from a signed token, so a request can never ask for another org
  • Segregation of duties down to the action: raising an invoice, receiving payment on it, and reversing it can each need a different permission
  • Every reversal or deletion is logged — who did it, when, and what the record said before
  • An automated suite tries to read across organizations on every release
  • Uploaded files are stored under your own organization’s path
Org-scopedEvery query filtered by your organization
Token-derivedScope comes from a signed token, never the request
SegregatedAround 50 permissions decide who can act, reverse, or only look
LoggedEvery reversal or deletion recorded with who, when, before and after
Rate-limitedLogin throttled, passwords hashed
Per-wing grantsAccess scoped to a business unit, not just a person

Questions, answered

Have you got SOC 2 or ISO 27001?

No — Sync doesn't hold a third-party compliance certification today, and we'd rather say that plainly than imply one. What's on this page is what the system actually does: organization-scoped data access, segregation of duties down to the individual action, and a logged audit trail on every reversal or deletion — verified by an automated cross-organization test suite on every release, not a once-a-year audit.

Is Sync GDPR-compliant?

Sync's data handling follows GDPR's core structure: a clear controller/processor split, the right to access, correct, export or delete your data, a defined retention period instead of indefinite storage, and no sale of personal data. GDPR itself isn't a certification you can hold — there's no badge to earn — so treat this as an accurate description of practice, not a compliance claim beyond what the words say. Full detail is in the Privacy Policy.

Can I see who reversed a specific payment?

Yes, if you're an admin — the audit log records who reversed it, when, and what the transaction said immediately before it was undone. It's the same mechanism behind every sensitive reversal or deletion in the product, not a one-off feature for bank transactions.

If I reverse a payment, does it actually undo everything it touched?

Yes — reversing a payroll payment, a loan disbursement, a bill, or a petty-cash top-up doesn't just delete a bank line. It restores the account balance and un-marks whatever it paid for — the payroll run, the loan, the bill — as unpaid again, in the same transaction. That's enforced in code and covered by an automated test for every one of those modules, not left to whoever's doing the reversing to remember to also go fix a separate system by hand.

Does giving someone "finance access" mean they can do everything in finance?

No. Creating an invoice, receiving payment against it, and reversing that payment are three separate permissions. The same split runs through every module that moves money or holds sensitive data — you decide how far each person's access goes, not the product.

Can I get my data out if I stop using Sync?

Yes. Every financial and HR report exports to PDF or CSV at any time, and you can request a full export or deletion of your data directly. Nothing is held hostage in a proprietary format.

Get started free

Ready to put your whole operation in sync?

Create your organization in a few minutes, or sign in if you're already set up. Your entire operation is one login away.

No credit card required · full platform from day one · cancel anytime