The controls we ship, and the claims we don’t make
Delivery data describes what is late, who is overloaded and where the money went. It deserves a straight answer about where it lives and who can reach it — so this page lists the controls that exist, and then lists what we are not claiming.
What the product controls
Identity and access
- Enterprise identity configuration with SSO and SAML sign-in
- SCIM provisioning and de-provisioning across the user lifecycle
- Tenant-scoped and project-scoped authorization on every request
- Role-aware navigation, so people see the surface their role owns
- Access-review campaigns with the decision recorded against a reviewer
AI governance
- Provider policy you set: models inside your tenant, or named external providers
- Authorized, scoped access to application context — never the whole tenant by default
- Source references on answers, and missing evidence shown as missing
- Human review on consequential recommendations, with the approver recorded
- No invented customer evidence, estimates, commitments or acceptance results
Data lifecycle
- Data-retention and lifecycle policies you configure per tenant
- Privacy-request intake with administrative review
- Integration credential protection, separate from application data
- Private attachment and evidence storage in S3-compatible buckets you control
Audit and operations
- Administrative and operational audit trails across the workspace
- Recorded approvals on requests, requirements, tests, gates and releases
- Integration health and operational diagnostics
- Organisation, centre, department, programme, project and team structure
What we are not claiming
Every one of these comes up in a security review. You should hear it from us first.
No SOC 2 or ISO 27001 certification
The controls above ship in the product. We hold no independent audit report, and we will not imply one.
No contractual uptime SLA on this page
Availability commitments belong in a contract, negotiated with your procurement team — not in marketing copy.
Private AI is a configuration, not a guarantee
Run models in your own tenant and nothing need reach an external provider. Enable one and data reaches it under the policy you set.
Integrations are not compliance boundaries
A connector inherits the permissions you grant it. What each one can reach differs, and it needs configuring against your systems.
No native mobile or offline mode
The workspace is browser-based. It works on a phone browser; there is no native app and no offline store.
Questions a security review asks
Is SyncupHUB SOC 2 or ISO 27001 certified?
No. SyncupHUB ships the access, audit, retention and AI-governance controls described on this page, but it does not hold an independent SOC 2 or ISO 27001 audit report, and we will not describe those controls as a certification.
Does our data reach an external AI provider?
Only if you allow one. SyncupHUB can run its models inside your own tenant, in which case delivery, people and governance data need not leave your environment at all. Where you do approve an external provider, it is named in policy and every access is recorded.
Can we self-host SyncupHUB?
Yes. The full platform can run inside your own infrastructure with a one-time setup and onboarding cost instead of recurring per-user licensing, which is the deployment most organisations with a strict data-residency requirement choose.
Who approves what the AI agents produce?
A person does. Agents prepare and propose — a requirement draft, a test recommendation, a deployment runbook, a capacity scenario — and a human accepts, amends or rejects it. Approving a capacity scenario does not move live allocations, and the release agents advise rather than deploy.
What audit evidence can we get out of it?
Administrative and operational audit trails, recorded approvals against requests, requirements, tests, quality gates and releases, access-review campaign decisions, and integration health diagnostics. Retention of that evidence follows the lifecycle policy you configure.