Skip to main content
Sytance logo
Trust

Security at Sytance

How Sytance approaches identity, tenant separation, data protection, secure development, monitoring, incident response, and vulnerability management.

Last updated 13 September 2026

Security approach

Sytance applies technical and organisational safeguards across the hosted service, software-development lifecycle, and supporting operations. Controls are selected and reviewed according to the information handled, the service architecture, credible threats, and the potential effect on customers.

This page is a public overview, not an audit report, certification, penetration-test result, or contractual security schedule. Customer-specific security, assurance, data-location, or notification requirements must be agreed through the applicable commercial process.

Identity and access

  • Access is based on individual user accounts and role-based permissions.
  • Customer administrators control membership and role assignment within their organisation and workspaces.
  • Requests for Customer Content are checked against tenant, workspace, and object-level access rules.
  • Authentication sessions use server-set HTTP-only cookies and production cross-site request protections.
  • Authorised administrative support access is scoped to the relevant customer context and recorded.

Tenant and data protection

  • Application and database controls reinforce separation between tenant-scoped records.
  • Production browser and API traffic is protected in transit through HTTPS at the public service boundary.
  • Customer files and media are delivered through authenticated routes rather than unrestricted public links.
  • Selected previews and downloads use time-limited access links.
  • Known credential, token, cookie, and secret fields are excluded from or redacted in normal application logs.
  • Data access is limited to the service function, customer instruction, support need, or operational responsibility that requires it.

Secure development and change

  • Security requirements and architecture considerations are incorporated into the design and review of relevant features.
  • Code review and automated checks support the identification of defects before deployment.
  • Changes are delivered through controlled build and deployment practices, with separation between development activity and production operation.
  • Dependencies and reported vulnerabilities are assessed according to their relevance, exploitability, exposure, and potential impact on the Service.

Monitoring and incident response

Security-relevant authentication, permission, administrative, application, and infrastructure events are recorded or monitored where appropriate to support detection, investigation, and accountability.

Authentication and selected public endpoints use rate limiting and abuse-prevention controls. Suspected incidents are assessed through a process covering triage, containment, investigation, remediation, recovery, and lessons learned.

If an incident requires customer or regulatory notification, we will provide it in accordance with applicable law and the relevant customer agreement.

For a suspected account compromise, contact support@sytance.com; for a suspected vulnerability or data exposure, contact security@sytance.com. Include the affected account or asset, time and observed behaviour, but do not send passwords, session tokens or unnecessary customer files. We may seek a secure method for exchanging additional evidence.

Where we process affected personal data for a Customer, incident notices and cooperation follow Appendix A to the Terms of Service. Initial notice is not delayed until every fact is established; subsequent information is supplied as the investigation progresses.

AI-assisted processing

AI-assisted actions run within authenticated product workflows. The service sends the instructions and workspace context relevant to the requested function, and the resulting output remains subject to customer review.

Vulnerability management

Potential vulnerabilities may be identified through development checks, operational monitoring, dependency information, customer or researcher reports, and targeted security assessment. Findings are validated and prioritised using risk factors including severity, exploitability, exposure, affected data and users, evidence of active exploitation, and available mitigations.

External researchers can report a suspected vulnerability through our coordinated disclosure process. The policy defines authorised research, reporting requirements, response targets, safe harbour, and disclosure coordination.

Shared responsibility

Customers remain responsible for administering users, reviewing access, protecting credentials and endpoints, deciding what information may be submitted, maintaining appropriate internal approvals and backups, configuring available controls, and reporting suspected compromise promptly.

Security enquiries and assurance

Customers and prospective customers can send proportionate security or assurance questions through hello@sytance.com or their established commercial contact. Existing customers should use support@sytance.com for suspected account compromise or an operational security issue.

Report a suspected vulnerability privately to security@sytance.com in accordance with the Vulnerability Disclosure Policy.

Security information may be shared under proportionate confidentiality and access arrangements to avoid exposing other customers or exploitable technical details. A request for assurance does not authorise penetration testing. Contractual audit rights and statutory regulator powers remain governed by the applicable agreement and law.