Trust Center

Trust starts with transparency.

Everything Syncora does to protect your data, govern our AI, and earn your team's trust — in one place.

Security

SOC 2 — Type 1 first, then Type 2Scoped · not yet audited
External penetration testScoped · not yet performed
ISO 27001Scoped · not yet audited
Encryption at rest + in transitAES-256 · TLS 1.3

Privacy

Regulatory landscape covered:

CCPACPRAVCDPACPACTDPAUCPATDPSAOCPAGDPRNY SHIELD+ 12 more state CDPAs

Coverage of the regulatory landscape — not a claim of certified compliance with each.

DSR portal for authenticated employeesLive
Data Processing Agreement (DPA)On request

AI Governance

AI Rules & Guardrails — explainability · human review · bias checksPublished
Governance Score — explainability, bias checks, human review, transparencyContinuously calculated
ISO 42001 AI Management SystemNot started
NYC Local Law 144 bias audit summaryNot yet performed
Colorado ADMT adverse-decision notices (SB 26-189)Built · required Jan 1, 2027
EU AI Act Annex IV technical documentationScoped

Sub-Processors

12sub-processors registered

30-day customer notification of changes per DPA.

Compliance Atlas

Coverage

192 / 6

regulations tracked · of 10 critical gaps closed in build

192 regulations tracked across federal + 50 states + DC + EU.

Updated quarterly; per-row last-verified dates visible in the app.

NYC Local Law 144 bias audit

No bias audit has been published yet. New York City Local Law 144 requires an independent bias audit before an automated employment decision tool is used on candidates in NYC, and it requires the summary to be posted publicly. We have not had that audit done, so we are not claiming it. When an independent audit is complete, the summary appears on the page below.

Methodology: All compliance status reviewed quarterly. Knowledge cutoff May 2025 — see methodology page for verification dates per regulation. NOT a legal opinion. Customers should engage their own counsel for jurisdiction-specific advice.