Security
Security you can read, not just trust
What we do, how we do it, and, just as plainly, what we haven't done yet.
Credentials
- API keys are stored only as peppered hashes. The secret is shown once, at creation, and never again.
- Browsers never see an API key. They get connection tokens scoped to one session and one user, which expire quickly.
- Passwords are stored as slow, salted hashes. Sessions use httpOnly cookies that scripts cannot read.
- Every route that mints a key requires a verified email address.
In transit
- All traffic is encrypted with TLS, and HSTS makes browsers refuse plaintext.
- Media travels over the same encrypted WebSocket. Tokens go in the WebSocket subprotocol, not the URL, so they stay out of logs.
Your data
- We relay and store media without decoding, inspecting or analysing it, and we never train models on it.
- Retention is set per project. Deleting a session or a project deletes its streams.
- One API call removes a single participant from a recording.
- Every request is scoped to one project. Keys from one project cannot read another's sessions.
Application hardening
- Rate limits are applied per API key and per client, and an abusive client is temporarily banned.
- Webhook targets are checked against private-network addresses, and every delivery is signed with HMAC-SHA256.
- This website sends a strict Content-Security-Policy, HSTS, and anti-framing and isolation headers.
- Production refuses to start with a default secret or a misconfigured billing key.
Where we are
Synento is in beta. We have done an internal pre-launch security review. We haven't yet had an external penetration test or a SOC 2 audit. Both are planned, and we won't claim them before they happen.
Report a vulnerability
Email security@synento.com. Our machine-readable contact details are in /.well-known/security.txt.
security@synento.com- We aim to acknowledge reports within three business days.
- We won't pursue legal action over good-faith research that avoids privacy violations, data destruction and service disruption.
- In scope: synento.com, app.synento.com, api.synento.com and the published SDKs.