SynthBridge
  • Services
  • About
  • Insights
  • Contact
  • Free Consultation

Trust Center

Trust & Compliance

The information procurement and security teams need to evaluate working with SynthBridge — our posture, our sub-processors, and the documents we can provide under NDA.

Company

Legal entitySynthBridge Consulting LLC
StructureSingle-member limited liability company, State of New Jersey, USA
Federal EIN42-2625670
NJ Entity ID0451466651
Principal activityInformation technology consulting (NAICS 541512 / 541611)
Registered office1127 Monmouth Ave, FL1, Linden, NJ 07036, USA

Compliance posture

Architecture

PCI DSS — SAQ A

Card payments run through a PCI DSS Level 1 processor via hosted fields. No card data touches our systems, so our scope is SAQ A by design.

On request

HIPAA

For healthcare engagements we act as a Business Associate and sign a BAA before any PHI is processed. We appoint a HIPAA Compliance Officer for those engagements.

On request

GDPR / DPA

We offer a Data Processing Agreement with Standard Contractual Clauses for clients who need one, and support data-subject request handling.

Inherited

Infrastructure certifications

Our hosting, payment, email, and AI sub-processors independently hold SOC 2 Type II and/or PCI DSS Level 1 certifications.

Honest scope statement. SynthBridge is a boutique consultancy, not an independently SOC 2–audited platform vendor. We do not claim our own SOC 2 or ISO 27001 certification. What we do provide is a security program built to those principles, hosted entirely on certified infrastructure, and documented so your team can assess it directly.

Sub-processors

We use a small set of vetted providers to operate our services. In line with our disclosure practice, we list them here by category and minimum certification. The specific named list is provided to clients under a Data Processing Agreement or NDA — disclosure to the data controller, not to the public.

CategoryFunctionMinimum standard
Cloud & edge infrastructureHosting, CDN, WAF, DDoS protectionSOC 2 Type II
Payment processingHosted card checkout & payoutsPCI DSS Level 1
Email deliveryTransactional & notification emailSOC 2 Type II
AI / ML servicesOptional content & automation featuresSOC 2 Type II

Data protection

  • In transit: TLS 1.2+/1.3 everywhere; HSTS enforced.
  • At rest: encryption provided by certified infrastructure.
  • Access: least-privilege, role-based, tenant-scoped, with append-only audit logging of administrative actions.
  • Credentials: salted + hashed (PBKDF2); optional two-factor authentication on admin accounts.
  • Data residency: primarily United States; regional handling can be discussed for specific engagements.
  • Retention & deletion: data is retained per contract and deleted on request or at end of engagement, subject to legal record-keeping.

Insurance & liability

Indemnification and limitation-of-liability terms are defined in our Master Services Agreement. Enterprise buyers who require a Certificate of Insurance can request one during procurement.

Documents available on request

DocumentHow to get it
Data Processing Agreement (DPA)On request for client engagements
Business Associate Agreement (BAA)On request for healthcare engagements
Named sub-processor listUnder DPA / NDA
CAIQ / security questionnaireUnder NDA for active procurement
Certificate of InsuranceOn request for enterprise procurement

Request a document or ask a question

Procurement, security review, or a signed agreement:

Email: security@synthbridge.net (compliance) · info@synthbridge.net (general)
Phone: +1 973-220-8280

See also our Security program, Privacy Policy, and Terms of Service.

SynthBridge

Strategic consulting in AI integration, data analytics, and digital transformation. Bridging the gap between where you are and where you need to be.

Company

  • About Us
  • Insights
  • Contact

Legal & Trust

  • Privacy Policy
  • Terms of Service
  • Security
  • Trust & Compliance

Contact

  • (973) 220-8280
  • [email protected]

© 2026 SynthBridge Consulting LLC. All rights reserved.