Company
| Legal entity | SynthBridge Consulting LLC |
|---|---|
| Structure | Single-member limited liability company, State of New Jersey, USA |
| Federal EIN | 42-2625670 |
| NJ Entity ID | 0451466651 |
| Principal activity | Information technology consulting (NAICS 541512 / 541611) |
| Registered office | 1127 Monmouth Ave, FL1, Linden, NJ 07036, USA |
Compliance posture
PCI DSS — SAQ A
Card payments run through a PCI DSS Level 1 processor via hosted fields. No card data touches our systems, so our scope is SAQ A by design.
HIPAA
For healthcare engagements we act as a Business Associate and sign a BAA before any PHI is processed. We appoint a HIPAA Compliance Officer for those engagements.
GDPR / DPA
We offer a Data Processing Agreement with Standard Contractual Clauses for clients who need one, and support data-subject request handling.
Infrastructure certifications
Our hosting, payment, email, and AI sub-processors independently hold SOC 2 Type II and/or PCI DSS Level 1 certifications.
Honest scope statement. SynthBridge is a boutique consultancy, not an independently SOC 2–audited platform vendor. We do not claim our own SOC 2 or ISO 27001 certification. What we do provide is a security program built to those principles, hosted entirely on certified infrastructure, and documented so your team can assess it directly.
Sub-processors
We use a small set of vetted providers to operate our services. In line with our disclosure practice, we list them here by category and minimum certification. The specific named list is provided to clients under a Data Processing Agreement or NDA — disclosure to the data controller, not to the public.
| Category | Function | Minimum standard |
|---|---|---|
| Cloud & edge infrastructure | Hosting, CDN, WAF, DDoS protection | SOC 2 Type II |
| Payment processing | Hosted card checkout & payouts | PCI DSS Level 1 |
| Email delivery | Transactional & notification email | SOC 2 Type II |
| AI / ML services | Optional content & automation features | SOC 2 Type II |
Data protection
- In transit: TLS 1.2+/1.3 everywhere; HSTS enforced.
- At rest: encryption provided by certified infrastructure.
- Access: least-privilege, role-based, tenant-scoped, with append-only audit logging of administrative actions.
- Credentials: salted + hashed (PBKDF2); optional two-factor authentication on admin accounts.
- Data residency: primarily United States; regional handling can be discussed for specific engagements.
- Retention & deletion: data is retained per contract and deleted on request or at end of engagement, subject to legal record-keeping.
Insurance & liability
Indemnification and limitation-of-liability terms are defined in our Master Services Agreement. Enterprise buyers who require a Certificate of Insurance can request one during procurement.
Documents available on request
| Document | How to get it |
|---|---|
| Data Processing Agreement (DPA) | On request for client engagements |
| Business Associate Agreement (BAA) | On request for healthcare engagements |
| Named sub-processor list | Under DPA / NDA |
| CAIQ / security questionnaire | Under NDA for active procurement |
| Certificate of Insurance | On request for enterprise procurement |
Request a document or ask a question
Procurement, security review, or a signed agreement:
Email: security@synthbridge.net (compliance) · info@synthbridge.net (general)
Phone: +1 973-220-8280
See also our Security program, Privacy Policy, and Terms of Service.