Draft — pending counselv0.1Effective Pending
DRAFT — for counsel review. Not legal advice, and not yet in effect.
Security Overview
Version 0.1 (draft) · Effective [Effective Date] · [Neivan Legal Entity, Inc.]
This Security Overview describes, in plain language, how Neivan protects the data entrusted to the Synapse platform. It is a trust-facing summary, not a contract, and does not modify the Agreement, the Data Processing Agreement, or any other terms between Neivan and a Customer. Where a statement describes a capability that is planned or in progress, it is marked [status: planned] so this document stays honest.
Throughout, 'Customer' means an organization that subscribes to Synapse, and 'Authorized Users' means that organization's administrators and employees.
1. Data Encryption
- In transit. Connections to Synapse are encrypted using TLS. Data moving between Authorized Users, Synapse, connected systems, and AI providers travels over encrypted channels.
- At rest. Customer data stored by Synapse is encrypted at rest.
- Key management. Encryption keys are managed server-side and are not exposed to Authorized Users or to the browser. Formal key-rotation policies and customer-managed encryption keys are [status: planned].
2. Access Control and Authentication
- Role-based access control (RBAC). Access within Synapse is governed by roles and permissions the Customer's administrators configure.
- Least privilege. Authorized Users and internal Neivan personnel are granted only the access they need.
- Admin audit logs. Administrative and security-relevant actions are recorded in audit logs so administrators can review who did what.
- Authentication. Authorized Users authenticate before access. Single sign-on (SSO/SAML) and enforced multi-factor authentication options are [status: planned].
3. Tenant Isolation
- Synapse is multi-tenant, and each Customer's data is logically separated so one Customer cannot access another's data.
- Access paths are scoped to a single tenant, and queries and storage are partitioned by tenant.
- Formal third-party validation of isolation boundaries is [status: planned].
4. Secrets Management
- Server-side vault. Sensitive credentials — including Customers' bring-your-own (BYO) AI-provider keys and the secrets for connected systems (email, calendar, drive, CRM, and custom APIs) — are stored in a server-side vault, never exposed to the browser.
- Payment data. Card payments are handled by Stripe. Card data is tokenized and never stored by Neivan (PCI DSS SAQ-A scope).
- Least exposure. Connection secrets are used only to perform the actions the Customer has authorized.
5. Application Security
- Input validation. Inputs are validated to reduce the risk of injection and malformed-data issues.
- Dependency management. Third-party dependencies are tracked and updated to address known vulnerabilities.
- Minimal data to AI providers. When an AI feature runs, only the prompts and content needed for that feature are sent to the selected AI provider (Anthropic, OpenAI, Google, Perplexity, Mistral, DeepSeek, or xAI). Customer content is not used to train provider models.
- A formal secure-development lifecycle and periodic third-party penetration testing are [status: planned].
6. Observation and Synapse Recorder Safeguards
Synapse can observe work to recommend automations. These features are built to be transparent and consent-first:
- Cloud activity observation captures activity metadata only — never the contents of messages or files — and is opt-in and consent-gated.
- Synapse Recorder (the desktop agent) captures the active window and accessibility metadata, and optional, redacted screen frames. It is consent-gated, with redaction and retention controls.
- Transparency to employees. Authorized Users can see when observation is active and what is captured. Observation requires consent and respects the scope the Customer configures.
- Retention. Captured observation data, including redacted frames, is subject to retention limits the Customer can configure.
7. Monitoring and Logging
- Security-relevant and administrative events are logged.
- Logs support investigation, audit, and incident response.
- Centralized log aggregation with automated anomaly alerting is [status: planned].
8. Vulnerability Management
- Dependencies are monitored for known vulnerabilities and updated.
- Reported security issues are triaged and remediated based on severity.
- A published coordinated vulnerability-disclosure program and a regular external penetration-testing cadence are [status: planned].
9. Data Retention and Deletion
- Customers can configure retention for observation and capture data.
- On termination, Customer data is returned or deleted in accordance with the Data Processing Agreement, subject to limited backup-rotation periods and any legally required retention.
- Self-service, in-product data-export and bulk-deletion tooling for administrators is [status: planned].
10. Business Continuity and Backups
- Customer data is backed up to support recovery.
- Backups are retained on a rotation schedule and then deleted or rendered inaccessible.
- Documented recovery-time and recovery-point objectives (RTO/RPO) and periodic restore testing are [status: planned].
11. Incident Response and Breach Notification
- Neivan maintains processes to detect, investigate, and respond to security incidents.
- In the event of a Personal Data Breach affecting a Customer's data, Neivan will notify the affected Customer without undue delay and provide the information reasonably available to help the Customer meet its obligations, as described in the Data Processing Agreement.
- A formal, regularly exercised incident-response runbook with defined severity tiers and on-call rotation is [status: planned].
12. Shared Responsibility
Security is a partnership. Neivan secures the platform; the Customer is responsible for how it configures and uses Synapse — including managing roles and permissions, setting consent and observation scope, choosing which systems to connect and which AI providers to enable, and safeguarding Authorized-User credentials.
This is a first-pass draft prepared for review and finalization by qualified legal counsel before use. It describes current and planned practices, does not constitute legal advice, and is not yet in effect. Direct questions to [[email protected]].