Trust
Built like it will be audited. Because it will be.
Security software on a control network has to be held to a higher standard than the network itself. Here is how we build and ship Synaptic vSOC, and how to report a problem to us.
Product security
Controls in every release.
These controls are part of the product and its build pipeline, not configuration you have to remember to turn on.
Signed offline installer
One bundle with container images, models, SBOMs and licences. Layered signatures and per-file SHA-256 are verified at install and fail closed.
No default credentials
Database, token, audit and integration secrets are generated on the host at install. The installer refuses to start if a default value is found.
Deny-by-default egress
Outbound connections are blocked unless the deployment tier allows them and the destination is on an allow-list. Tier 1 never connects out.
Zero-packet safety gate
An automated code check blocks any dependency that could open a connection to a controller or build an active driver.
Software bill of materials
CycloneDX 1.5 and SPDX 2.3 SBOMs with every release. No GPL, AGPL, SSPL or BUSL code in the shipped runtime.
Tamper-evident records
The audit log is HMAC-chained per tenant. Evidence packs are signed with Ed25519, with optional TPM-sealed keys.
Identity and access
SSO with SAML or OIDC, TOTP multi-factor authentication and role-based workspaces with tenant isolation enforced in code.
Signed licences
Licences are signed files verified on the appliance. No call to us is needed to activate or renew in an air-gapped site.
AI model policy
The AI assistant runs inside the deployment. Models from a blocked-origin list cannot be bundled or installed.
Regulatory readiness
How we meet our own obligations.
These cover Synaptic OT as a software supplier. For the frameworks the platform helps you meet, see compliance by region.
EU AI Act
The AI assistant only annotates. Detection is deterministic and a person approves every action, which supports the Act’s human-oversight expectations. Readiness documentation available.
EU Cyber Resilience Act
Software bills of materials (CycloneDX 1.5 and SPDX 2.3) with every release, signed updates and a published vulnerability disclosure process.
GDPR
Data minimisation on this website and no customer OT data processed by us. Readiness documentation available.
ISO/IEC 27001, SOC 2, IEC 62443
Readiness documentation maintained. Independent certifications are not yet held.
Assurance
Where we are, stated plainly.
We maintain readiness documentation for IEC 62443, ISO 27001, SOC 2, GDPR and the EU AI Act, and a documented threat model. An independent third-party penetration test of the product is scheduled; we will publish a summary when it is complete.
Customers and qualified prospects can request the SBOMs, the threat model summary and the readiness documents under NDA.
Vulnerability disclosure
Report a security issue.
If you believe you have found a vulnerability in Synaptic vSOC or on synapticot.com, email security@synapticot.com. Please include:
- the affected product version or URL;
- steps to reproduce, and proof of concept if you have one;
- the impact you believe it has; and
- how you would like to be credited, if at all.
What we ask
- Give us reasonable time to fix the issue before you disclose it publicly. We aim for 90 days and will agree a date with you.
- Do not access, change or delete data that is not yours, and stop as soon as you have confirmed the issue.
- Do not test against any customer deployment or any operational technology. Never send traffic to industrial equipment you do not own.
- No denial-of-service, social engineering or physical testing.
What we commit to
- We aim to acknowledge your report within three business days and keep you updated as we work on it.
- We will not take legal action against research carried out in good faith within this policy.
- With your permission, we will credit you when we publish a fix.
Our security.txt lists the same contact in machine-readable form.