Security you can verify — not security you have to take our word for.

Enterprise R&D teams trust SuntheticsML with their most sensitive asset: proprietary experimental data. This page shows exactly how we protect it, backed by independent audits and live, continuously monitored controls.

At A Glance

SOC 2

Independently audited by a licensed CPA firm

Continuous monitoring

Controls verified continuously via Vanta, not once a year

Independent penetration testing

Third-party security testing of the platform

GDPR-ready

Appointed EU & UK representatives

Hosted on AWS

Enterprise-grade cloud infrastructure

Your Data Stays Yours

The question every R&D leader asks first; so we answer it first.

You own your data

Your experimental data, and the results and models generated from it, belong to you.

Your data is not shared with other customers.

Datasets, campaigns, and the models built from them are kept separate per customer — your competitive edge stays yours.

Clean exit.

If you leave, your data is returned and/or deleted in accordance with your agreement.

No surprise subprocessors.

Our subprocessor list is published in our live Trust Center and kept current.

Platform Security

Infrastructure

SuntheticsML runs on Amazon Web Services. We inherit AWS's physical security, network protections, and compliance certifications — and build our own controls on top.

Encryption

Customer data is encrypted in transit and at rest using industry-standard encryption.

Access control

Access to internal systems is protected by single sign-on and multi-factor authentication. Internal access to customer data follows least-privilege principles and is logged.

Independent testing

A third-party security firm performs penetration testing of the platform. Findings are tracked and remediated on defined timelines

Compliance & Certifications

SOC 2

Sunthetics has completed a SOC 2 audit conducted by an independent licensed CPA firm against the AICPA Trust Services Criteria. The report is available to customers and qualified prospects under NDA — request it through our Trust Center or at compliance@sunthetics.io.

Continuous compliance

We use Vanta to monitor our security controls continuously. Our live Trust Center shows control status in near-real-time — not a once-a-year snapshot.

GDPR

We maintain appointed EU and UK representatives, support data subject rights, and offer data processing agreements for customers handling EU/UK personal data.

Always expanding

Our compliance program grows with our customers — we actively evaluate additional frameworks as our enterprise and government work expands.

People & Process

Background checks on new hires
Regular security awareness training for employees
Centrally managed and monitored company devices
Documented incident response plan — affected customers are notified in accordance with contractual and legal obligations
Risk reviews of critical vendors and subprocessors

Report A Vunerability

Found something? We want to know. Report security concerns to compliance@sunthetics.io or through our Report a Concern page. We acknowledge reports promptly and keep reporters informed through resolution.

Frequently Asked Questions

Who do we contact with security questions?
Will you complete our security questionnaire?
Is our data used for other customers?
Where is our data stored?
Can we see your SOC 2 report?

Security review coming up?

Point your team to our live Trust Center for real-time control status, policies, and documentation — or reach us directly at compliance@sunthetics.io.