Security & access
Data isolation, data privacy, segregation of duties, and a full audit trail
The things a controller, an auditor, or a security-conscious buyer actually asks about — described as what the system does, not a compliance badge we haven't earned.
Segregation of duties
One permission for the action, a different one for undoing it
Finance access" or "HR access" isn't one flag here — around fifty separate permissions decide exactly how far each person's access goes, granted per business wing. A few of the splits that actually exist in the product today:
Processing a payroll run
≠ Reversing one that's already paid
Two separate permissions — someone can run payroll every month without ever being able to unwind one.
Recording a bank transaction
≠ Deleting or reversing one
Same split across every money-movement module — banks, credit card, petty cash, travel, perks.
Viewing a client record
≠ Editing, deleting, or merging one
View access never implies write access — a directory anyone can browse, not everyone can change.
Marking an employee as left
≠ Resetting their portal login password
An HR lead can offboard someone without ever touching login credentials — that stays admin-only.
Audit trail
Every reversal and deletion leaves a record
Undoing something — a bank transaction, a payroll run, a client record — is exactly where "who did this and why" matters most. Sync logs it automatically, in the same database transaction as the change itself, so an audit entry can never exist without the change it describes, or vice versa.
It covers reversing a bank, credit card, petty cash, or travel payment, deleting a payroll run, a trip, or a client record, marking a resource as left or reactivating them, and any other action gated behind a sensitive, individually-grantable permission. Admins can look up the full history for any record.
Data & privacy
How your data is actually handled
No certification is claimed here — none is held. This is a plain description of what the product and the Privacy Policy actually commit to.
You control your data; we process it on your instruction
For your own account, Sync is the data controller. For everything you enter about your employees, clients or vendors, your organization is the controller and Sync acts only as a processor — we handle that data to run the Service, under your instructions, not our own.
Access, export or delete — on request
You can request access to, correction of, export of, or deletion of personal data at any time. Every financial and HR report exports to PDF or CSV on demand, so your records were never locked into the product in the first place.
We don't sell data, and we don't use ad-tech
No tracking or advertising cookies, no data brokers, no sharing with third parties for their own marketing. Data goes to Stripe (billing), our transactional email and hosting providers, and — only if you use Ask Sync — our AI provider, which receives just the organization data needed to answer that one question and never uses it to train their models.
Passwords are hashed, sessions are protected
Passwords are stored as a bcrypt hash, never in plain text. Login is rate-limited, and two-factor authentication is available on every account.
A defined retention policy, not indefinite storage
Data is retained while your account is active. Cancel, and it's kept only long enough for you to reactivate or export it, then deleted from active systems — or sooner, on request.
Built for more than one company
Your books stay yours
The business next door could be on Sync too. That's not something you have to take our word on — separation isn't a setting someone can misconfigure, it's how every query is written. Inside your own organization, segregation of duties works the same way: who can act, who can reverse it, and a logged trail of both.
- Your data is filtered by organization at the query itself — not hidden in the interface
- That scope is read from a signed token, so a request can never ask for another org
- Segregation of duties down to the action: raising an invoice, receiving payment on it, and reversing it can each need a different permission
- Every reversal or deletion is logged — who did it, when, and what the record said before
- An automated suite tries to read across organizations on every release
- Uploaded files are stored under your own organization’s path
Questions, answered
Have you got SOC 2 or ISO 27001?
No — Sync doesn't hold a third-party compliance certification today, and we'd rather say that plainly than imply one. What's on this page is what the system actually does: organization-scoped data access, segregation of duties down to the individual action, and a logged audit trail on every reversal or deletion — verified by an automated cross-organization test suite on every release, not a once-a-year audit.
Is Sync GDPR-compliant?
Sync's data handling follows GDPR's core structure: a clear controller/processor split, the right to access, correct, export or delete your data, a defined retention period instead of indefinite storage, and no sale of personal data. GDPR itself isn't a certification you can hold — there's no badge to earn — so treat this as an accurate description of practice, not a compliance claim beyond what the words say. Full detail is in the Privacy Policy.
Can I see who reversed a specific payment?
Yes, if you're an admin — the audit log records who reversed it, when, and what the transaction said immediately before it was undone. It's the same mechanism behind every sensitive reversal or deletion in the product, not a one-off feature for bank transactions.
If I reverse a payment, does it actually undo everything it touched?
Yes — reversing a payroll payment, a loan disbursement, a bill, or a petty-cash top-up doesn't just delete a bank line. It restores the account balance and un-marks whatever it paid for — the payroll run, the loan, the bill — as unpaid again, in the same transaction. That's enforced in code and covered by an automated test for every one of those modules, not left to whoever's doing the reversing to remember to also go fix a separate system by hand.
Does giving someone "finance access" mean they can do everything in finance?
No. Creating an invoice, receiving payment against it, and reversing that payment are three separate permissions. The same split runs through every module that moves money or holds sensitive data — you decide how far each person's access goes, not the product.
Can I get my data out if I stop using Sync?
Yes. Every financial and HR report exports to PDF or CSV at any time, and you can request a full export or deletion of your data directly. Nothing is held hostage in a proprietary format.
Get started free
Ready to put your whole operation in sync?
Create your organization in a few minutes, or sign in if you're already set up. Your entire operation is one login away.
No credit card required · full platform from day one · cancel anytime