Skip to content

Security

Security you can read, not just trust

What we do, how we do it, and, just as plainly, what we haven't done yet.

Credentials

  • API keys are stored only as peppered hashes. The secret is shown once, at creation, and never again.
  • Browsers never see an API key. They get connection tokens scoped to one session and one user, which expire quickly.
  • Passwords are stored as slow, salted hashes. Sessions use httpOnly cookies that scripts cannot read.
  • Every route that mints a key requires a verified email address.

In transit

  • All traffic is encrypted with TLS, and HSTS makes browsers refuse plaintext.
  • Media travels over the same encrypted WebSocket. Tokens go in the WebSocket subprotocol, not the URL, so they stay out of logs.

Your data

  • We relay and store media without decoding, inspecting or analysing it, and we never train models on it.
  • Retention is set per project. Deleting a session or a project deletes its streams.
  • One API call removes a single participant from a recording.
  • Every request is scoped to one project. Keys from one project cannot read another's sessions.

Application hardening

  • Rate limits are applied per API key and per client, and an abusive client is temporarily banned.
  • Webhook targets are checked against private-network addresses, and every delivery is signed with HMAC-SHA256.
  • This website sends a strict Content-Security-Policy, HSTS, and anti-framing and isolation headers.
  • Production refuses to start with a default secret or a misconfigured billing key.

Where we are

Synento is in beta. We have done an internal pre-launch security review. We haven't yet had an external penetration test or a SOC 2 audit. Both are planned, and we won't claim them before they happen.

Report a vulnerability

Email security@synento.com. Our machine-readable contact details are in /.well-known/security.txt.

security@synento.com
  • We aim to acknowledge reports within three business days.
  • We won't pursue legal action over good-faith research that avoids privacy violations, data destruction and service disruption.
  • In scope: synento.com, app.synento.com, api.synento.com and the published SDKs.