Security at GB7 SYNQ
An honest look at how we protect data today, while we're still in early access — and what we're building toward.
Encryption in transit
Traffic between your browser and GB7 SYNQ is encrypted using HTTPS/TLS. We do not accept unencrypted connections to any part of the product or this website in production.
Access controls
Access to data inside GB7 SYNQ is scoped by organization and by Space. Every Space has a membership list and a role (Owner, Admin, Member, Guest at the organization level; View, Comment, Edit, or Full Access within a Space), and access checks are enforced on every request — not just hidden in the interface.
Internally, engineering access to production data is limited to what's needed to operate and support the service, and is not open by default.
Audit logging
Administrative and security-relevant actions — such as membership changes and organization-level settings — are recorded in an audit log with the actor, action, target, timestamp, and originating IP address, so that changes to sensitive settings are traceable.
Password and session security
Account passwords are never stored in plain text. Sessions are backed by randomly generated tokens with expiration, and session cookies are marked HTTP-only to reduce exposure to client-side script injection.
Data isolation
Data belonging to one organization is not visible to another organization. Every query that reads or writes application data is scoped to the requesting user's organization and permissions.
Vulnerability reports
If you believe you've found a security issue in GB7 SYNQ or this website, please tell us via our contact page with as much detail as you can provide. We take reports seriously and will respond as quickly as we can. Please avoid accessing, modifying, or deleting data that isn't yours while investigating an issue.
What we're building toward
As GB7 SYNQ moves from early access toward general availability, we plan to formalize our security practices further, including regular third-party review. This page will be updated as that work progresses — we won't claim a certification here until it's actually been earned.
Questions about our security practices?
We're happy to talk through specifics before you commit to early access.
Contact us