Enterprise R&D teams trust SuntheticsML with their most sensitive asset: proprietary experimental data. This page shows exactly how we protect it, backed by independent audits and live, continuously monitored controls.
At A Glance
SOC 2
Independently audited by a licensed CPA firm
Continuous monitoring
Controls verified continuously via Vanta, not once a year
Independent penetration testing
Third-party security testing of the platform
GDPR-ready
Appointed EU & UK representatives
Hosted on AWS
Enterprise-grade cloud infrastructure
Your Data Stays Yours
The question every R&D leader asks first; so we answer it first.
You own your data
Your experimental data, and the results and models generated from it, belong to you.
Your data is not shared with other customers.
Datasets, campaigns, and the models built from them are kept separate per customer — your competitive edge stays yours.
Clean exit.
If you leave, your data is returned and/or deleted in accordance with your agreement.
No surprise subprocessors.
Our subprocessor list is published in our live Trust Center and kept current.
Platform Security
Infrastructure
SuntheticsML runs on Amazon Web Services. We inherit AWS's physical security, network protections, and compliance certifications — and build our own controls on top.
Encryption
Customer data is encrypted in transit and at rest using industry-standard encryption.
Access control
Access to internal systems is protected by single sign-on and multi-factor authentication. Internal access to customer data follows least-privilege principles and is logged.
Independent testing
A third-party security firm performs penetration testing of the platform. Findings are tracked and remediated on defined timelines
Compliance & Certifications
SOC 2
Sunthetics has completed a SOC 2 audit conducted by an independent licensed CPA firm against the AICPA Trust Services Criteria. The report is available to customers and qualified prospects under NDA — request it through our Trust Center or at compliance@sunthetics.io.
Continuous compliance
We use Vanta to monitor our security controls continuously. Our live Trust Center shows control status in near-real-time — not a once-a-year snapshot.
GDPR
We maintain appointed EU and UK representatives, support data subject rights, and offer data processing agreements for customers handling EU/UK personal data.
Always expanding
Our compliance program grows with our customers — we actively evaluate additional frameworks as our enterprise and government work expands.
People & Process
Background checks on new hires
Regular security awareness training for employees
Centrally managed and monitored company devices
Documented incident response plan — affected customers are notified in accordance with contractual and legal obligations
Risk reviews of critical vendors and subprocessors
Report A Vunerability
Found something? We want to know. Report security concerns to compliance@sunthetics.io or through our Report a Concern page. We acknowledge reports promptly and keep reporters informed through resolution.
Frequently Asked Questions
Who do we contact with security questions?
compliance@sunthetics.io — we typically respond within one business day.
Will you complete our security questionnaire?
Yes — we complete standard and custom security questionnaires promptly, and our live Trust Center answers most questions instantly.
Is our data used for other customers?
No. Your datasets and the models generated from them are kept separate per customer.
Where is our data stored?
On Amazon Web Services. If your organization has data residency requirements, contact us — we'll walk you through our architecture.
Can we see your SOC 2 report?
Yes — under NDA, through our live Trust Center or compliance@sunthetics.io.
Security review coming up?
Point your team to our live Trust Center for real-time control status, policies, and documentation — or reach us directly at compliance@sunthetics.io.