Security overview
Shared responsibility
Synthex uses reasonable safeguards for a managed production workflow, while clients control what they submit, how links are shared and who can publish. No provider can guarantee absolute security. The safest workflow uses minimum access, time-limited sharing and no passwords in SYNTHEX Workspace or ordinary support fields.
1. Administrative and technical controls
- Role-appropriate access to production information and provider accounts.
- Authentication and account-security practices appropriate to the provider.
- Encrypted transport where supported by website, storage and production providers.
- Operational logs, status records and access review for key workflows.
- Backups or recovery methods for critical business records, while clients remain responsible for source originals.
- Incident escalation, provider review and change control for material workflow updates.
2. Service providers
The workflow may rely on hosting, cloud storage, payment, email, automation, audio, transcription, clipping and rendering providers. We evaluate providers according to the data and function involved, available security information, access options and contractual terms. We seek to limit data to what is needed for the task.
Provider infrastructure, subprocessors and features may change. We may replace a provider with a reasonably equivalent service. A client with special vendor, residency, regulated-data or enterprise-security requirements must disclose them before purchase so we can determine whether the service is appropriate.
3. Client access practices
- Use share links that are limited to the needed files and revoke them after delivery.
- Prefer supported delegated or role-based account connections through SYNTHEX Workspace for social and reporting workflows.
- Do not send account passwords, backup codes or one-time authentication codes.
- Remove private segments and unrelated confidential files before sharing.
- Use a separate business account for collaboration where practical.
- Notify us promptly when an employee or contractor should lose access.
4. Content handling and retention
Source content is accessed for review and production, then transferred through the tools necessary for accepted scope. Working files may exist in storage, automation logs, processing systems and rendered outputs. We aim to avoid unnecessary copies and remove or archive production data according to operational and legal needs.
Synthex is not intended to serve as the client’s permanent archive. Clients should retain source masters and final deliveries. If deletion at a particular milestone is legally or contractually required, that must be agreed before production because backups and provider retention can limit immediate deletion.
5. Sensitive and regulated information
Standard Synthex service is not designed for protected health information, payment-card storage, government secrets, biometric databases or other highly regulated datasets. Professionals should edit or redact sensitive portions before submission. Do not assume a business associate agreement, data-processing addendum or sector-specific certification exists unless signed in writing.
Do not submit
- Patient records or client case files embedded in production notes.
- Full card numbers, bank credentials or tax identifiers.
- Passwords, recovery codes or secret API keys.
- Unredacted documents unrelated to the final public content.
6. Incident response
A security incident is an event that compromises or is reasonably suspected to compromise confidentiality, integrity or availability of information under our control. We triage reported events, preserve relevant evidence, contain access where possible, coordinate with providers, assess impact and provide legally required notice.
If you suspect an incident, email admin@synthexsystemshub.com with “Security incident” in the subject. Include what happened, when, affected accounts/files and safe contact information. Do not send the exposed secret itself.
7. Availability and business continuity
We use reasonable efforts to maintain the production workflow, but do not guarantee uninterrupted availability. Internet failures, provider outages, platform changes, account restrictions, natural events and maintenance can delay work. We prioritize preserving source integrity, communicating material delays and using reasonable alternatives.
8. Vulnerability reporting
Good-faith reports should avoid accessing, modifying or downloading other people’s data, disrupting service, social engineering or extortion. Send a reproducible description and impact to the security contact. We do not authorize testing against third-party providers through this policy.