Skip to main content

Trust Center

How we protect your data, your patients, and your audit.

Synaptis Technologies builds healthcare AI on a foundation that is auditable, attestable, and continuously reviewed. This Trust Center documents our security posture, compliance status, data handling, subprocessors, and how we measure the outcomes we publish.

At-a-glance posture

  • HIPAA

    BAA available; controls operational

    All PHI processed via the Synaptis platform

    Synaptis operates under HIPAA as a Business Associate. Signed BAAs are available before any PHI is exchanged. Required Security Rule controls are operational and reviewed annually.

  • SOC 2 Type II

    Audit in progress — target Q4 2026

    Synaptis platform + AXIFI

    We are in active SOC 2 Type II engagement with a recognized auditor. Type I report available on request under NDA; Type II expected Q4 2026.

  • GDPR

    Operational; DPA available

    EU data subject interactions

    Synaptis serves as data processor under GDPR for any EU data subjects routed through customer deployments. Standard contractual clauses and DPA available on request.

  • FDA 21 CFR Part 11

    Applied to AXIFI regulated-workflow surfaces

    Electronic records + electronic signatures in AXIFI clinical workflows

    Where AXIFI workflows produce records subject to Part 11, the platform supports the required electronic signature, audit trail, and record integrity controls.

  • Penetration testing

    Annual third-party pen test; latest 2026

    External + internal black-box + grey-box

    Annual third-party penetration test against the Synaptis platform. Latest executed Q1 2026. Summary report available on request under NDA.

    Request pen-test summary
  • ISO 27001

    Policy framework documented; certification planned

    Management system

    We have an ISMS policy framework aligned to ISO 27001 controls. Certification is on the post-SOC 2 roadmap.

Security packet

Detailed security documentation, SOC 2 Type I report (where applicable), pen-test summary, BAA template, DPA template, and subprocessor list. Available on signed NDA.

Need something specific?

Talk to our security team.

We can walk you through our controls, share applicable reports under NDA, and answer vendor security questionnaires directly.