New · Wire DVR with time-travel retro-hunt: rewind the plant network to the second it mattered →
SYNAPTIC OT Secure · Monitor · Protect

Trust

Built like it will be audited. Because it will be.

Security software on a control network has to be held to a higher standard than the network itself. Here is how we build and ship Synaptic vSOC, and how to report a problem to us.

Product security

Controls in every release.

These controls are part of the product and its build pipeline, not configuration you have to remember to turn on.

Signed offline installer

One bundle with container images, models, SBOMs and licences. Layered signatures and per-file SHA-256 are verified at install and fail closed.

No default credentials

Database, token, audit and integration secrets are generated on the host at install. The installer refuses to start if a default value is found.

Deny-by-default egress

Outbound connections are blocked unless the deployment tier allows them and the destination is on an allow-list. Tier 1 never connects out.

Zero-packet safety gate

An automated code check blocks any dependency that could open a connection to a controller or build an active driver.

Software bill of materials

CycloneDX 1.5 and SPDX 2.3 SBOMs with every release. No GPL, AGPL, SSPL or BUSL code in the shipped runtime.

Tamper-evident records

The audit log is HMAC-chained per tenant. Evidence packs are signed with Ed25519, with optional TPM-sealed keys.

Identity and access

SSO with SAML or OIDC, TOTP multi-factor authentication and role-based workspaces with tenant isolation enforced in code.

Signed licences

Licences are signed files verified on the appliance. No call to us is needed to activate or renew in an air-gapped site.

AI model policy

The AI assistant runs inside the deployment. Models from a blocked-origin list cannot be bundled or installed.

Regulatory readiness

How we meet our own obligations.

These cover Synaptic OT as a software supplier. For the frameworks the platform helps you meet, see compliance by region.

EU AI Act

The AI assistant only annotates. Detection is deterministic and a person approves every action, which supports the Act’s human-oversight expectations. Readiness documentation available.

EU Cyber Resilience Act

Software bills of materials (CycloneDX 1.5 and SPDX 2.3) with every release, signed updates and a published vulnerability disclosure process.

GDPR

Data minimisation on this website and no customer OT data processed by us. Readiness documentation available.

ISO/IEC 27001, SOC 2, IEC 62443

Readiness documentation maintained. Independent certifications are not yet held.

Assurance

Where we are, stated plainly.

We maintain readiness documentation for IEC 62443, ISO 27001, SOC 2, GDPR and the EU AI Act, and a documented threat model. An independent third-party penetration test of the product is scheduled; we will publish a summary when it is complete.

Customers and qualified prospects can request the SBOMs, the threat model summary and the readiness documents under NDA.

Request security documentation →

Vulnerability disclosure

Report a security issue.

If you believe you have found a vulnerability in Synaptic vSOC or on synapticot.com, email security@synapticot.com. Please include:

  • the affected product version or URL;
  • steps to reproduce, and proof of concept if you have one;
  • the impact you believe it has; and
  • how you would like to be credited, if at all.

What we ask

  • Give us reasonable time to fix the issue before you disclose it publicly. We aim for 90 days and will agree a date with you.
  • Do not access, change or delete data that is not yours, and stop as soon as you have confirmed the issue.
  • Do not test against any customer deployment or any operational technology. Never send traffic to industrial equipment you do not own.
  • No denial-of-service, social engineering or physical testing.

What we commit to

  • We aim to acknowledge your report within three business days and keep you updated as we work on it.
  • We will not take legal action against research carried out in good faith within this policy.
  • With your permission, we will credit you when we publish a fix.

Our security.txt lists the same contact in machine-readable form.