generated: '2026-08-13' method: searched probe: true url: https://security.synthflow.ai/ name: Synthflow Trust Vault description: >- Synthflow operates a Trust Vault at security.synthflow.ai holding compliance documents, subprocessors and control details. The vault itself renders client-side (an unauthenticated fetch returns only the title "Trust Vault"), and some documents require Login / Get Access, so the certification list below is taken from Synthflow's own documentation page, which names them explicitly. certifications: - ISO 27001:2022 - SOC 2 - GDPR - HIPAA - PCI DSS v4.0.1 access: public_landing: true documents_gated: true gate: 'Login / Get Access on the vault for private documents' subprocessors_published: true related: baa: https://docs.synthflow.ai/baa baa_note: 'Business Associate Agreement available for HIPAA customers.' agent_level_controls: https://docs.synthflow.ai/security-and-compliance ai_transparency: https://docs.synthflow.ai/ai-transparency gdpr: https://synthflow.ai/gdpr enterprise_controls: sso: available: true plan: Enterprise provider: WorkOS protocols: [SAML] identity_providers: [Okta, Entra ID, Google SAML, Auth0] two_factor: available: true type: TOTP workspace_enforcement: true note: 'Where a workspace mandates 2FA, a user must enable it before creating or viewing API keys.' allowed_email_domains: true msa_dpa: 'MSA/DPA support and data-handling review are scoped in enterprise contracts.' data_protection: pii_redaction: true pii_redaction_api_field: redact_pii redacted_types: ['credit card numbers, expiry and CVV', 'social security numbers', 'names', 'email addresses', 'phone numbers', 'physical addresses'] retention_control: 'Optional 30-day auto-delete of transcripts, recordings and caller IDs.' regional_residency: ['Global', 'United States', 'European Union'] residency_note: >- Region is enforced at the API and MCP host level. WhatsApp and SMS chat channels are US-only because Twilio does not offer EU data residency for those Conversations APIs. evidence: - {source: 'https://docs.synthflow.ai/security', kind: docs, detail: 'Names ISO 27001:2022, SOC 2, GDPR, HIPAA and PCI DSS V4.0.1 and links the Trust Vault.'} - {source: 'https://security.synthflow.ai/', kind: trust-center, http_status: 200, detail: 'Client-rendered Trust Vault; body served to an anonymous fetch contains only the page title.'} - {source: 'https://synthflow.ai/pricing', kind: marketing, detail: 'Footer links Security; enterprise security review named in contract scope.'} x-evidence: fetched: '2026-08-13' probes: - {url: 'https://security.synthflow.ai/', status: 200} - {url: 'https://docs.synthflow.ai/security.md', status: 200} - {url: 'https://docs.synthflow.ai/security-and-compliance.md', status: 200} note: >- The mechanical probe (0-working/probe-security-programs.py) recorded trust=none because the Trust Vault is a single-page app and its keyword check found no compliance terms in the served HTML. This file is written from the provider's own documentation instead, which states the certifications in plain text.