Security & Data Protection

We ask for the access we need, and no more.

A small workflow build and an ongoing managed service do not need the same access. We agree the access model before work starts.

Working principles

Access should match the work.

Least privilege

Access should match the systems, permissions and time needed for the agreed work.

Named accounts

Where the platform allows it, we prefer named accounts so activity can be tied to a person.

MFA

We use the client's approved identity controls and MFA where the environment supports them.

Keep secrets out of ordinary channels

Passwords, tokens and private keys should not be sent through public website forms or stored in normal project documents or source code.

Treat production differently

Development, test and production have different risks. Production access is agreed before it is granted.

Leave evidence

Important changes, testing and operating notes are recorded when the work requires it.

Access models

Not every project needs live personal data.

No production-data access

Build or test with synthetic, anonymised or client-prepared data, then let the client's authorised team deploy or approve the change.

Limited approved access

Use a named, time-bounded account when live troubleshooting or configuration genuinely needs it.

Ongoing managed access

For managed services, agree the systems, roles, privileged actions, escalation path and review process in advance.

Personal data

The role depends on the engagement.

For the public website, Syntix is the controller for the inquiry and recruitment data described in the Privacy Notice.

For client work, Syntix may be a processor or subprocessor when it handles personal data on the client's instructions. The applicable agreement sets out what is processed, why, who can access it and what happens when the work ends.

International access

Syntix works from Pakistan.

Cross-border access, transfer requirements and country-specific restrictions are covered on the International Delivery page.

Read the international delivery model →

Incident handling

If there is an incident, we act on it.

We contain the issue, preserve useful evidence, tell the right client contact and follow the incident process agreed for the engagement. Contractual notification duties stay in the contract and the client's incident procedure.

Website infrastructure

The company website is separate from client production environments.

The current Syntix website uses Cloudflare for delivery and security. Public inquiry records are stored in a dedicated Syntix company-website Supabase project whose current primary database region is Singapore. Email notifications may be sent through Resend if that feature is configured.

These website providers do not define the architecture or data location of a client environment.

Procurement or security review?

Share the required controls before access is granted.

Start a review