Skip to content

Legal

Security

We hold other people's money, so security is an operating constraint rather than a feature. These are the controls we run and how to tell us if you find a gap.

Controls

How the platform is protected

SOC 2 Type II

Independently audited

Our security, availability and confidentiality controls are audited over a twelve month observation period. The report is available under NDA.

In transit and at rest

Encrypted throughout

All traffic uses TLS 1.3. Data at rest is encrypted with AES-256, and keys are managed in a hardware security module with rotation.

Required

Two factor on every account

Dashboard access requires a second factor. We support hardware keys and authenticator apps, and we do not use SMS for authentication.

Least privilege

Access is scoped and logged

Internal access to production is time bound, approved per request, and logged. No engineer holds standing access to customer data.

Maker checker

No single person moves money

Payouts above the threshold you set require a second approver, and the approval chain is recorded on the payout itself.

Continuous

Tested by outsiders

We run annual penetration tests with an independent firm and a continuous bug bounty. Findings are triaged within one working day.

01Reporting a vulnerability

Send details to security@syntrapayments.com, including steps to reproduce and anything needed to demonstrate impact. Encrypt your report with our published PGP key if it contains sensitive detail.

We acknowledge every report within one working day and give you a named contact for the duration of the investigation.

02What we ask of you

Test against the sandbox rather than production wherever possible, and never access, modify or retain data belonging to another customer.

Give us reasonable time to fix an issue before disclosing it publicly. We will agree a disclosure date with you rather than impose one.

03What you can expect from us

We will not pursue legal action against researchers who follow this policy in good faith.

We pay bounties based on severity and quality of the report, and we credit researchers publicly when they want to be named.