Trust · Security & Compliance
What we're certified for, and what we're not.
Most vendor security pages are a wall of logos. This one is a list of what we hold, a description of how we actually operate, and an explicit list of things we don't claim. Ask for any of the underlying documents and we'll send them.
Certifications
Nothing held yet. Everything in progress, said plainly.
No certification is displayed as held until the report or certificate exists — every row above is work in progress, and the section below describes how we operate in the meantime. Audit evidence to date is available under NDA.
Security Posture
How we operate, independent of any certificate.
Where your data lives
In your cloud tenancy, under your account, in the region you choose. We do not copy production data to Vietnam. Where an engagement requires us to hold data, it stays in the region you specify and is deleted on completion with written confirmation.
Access control
Role-scoped per engagement, least privilege, MFA enforced without exception, sessions logged. Access granted at engagement start and revoked at engagement end through a documented process, not by memory.
Encryption
At rest and in transit, using your key management where you have it. TLS 1.2 minimum, 1.3 preferred.
Endpoints and network
Managed devices with disk encryption, EDR and enforced patching. No engagement work on personal machines. Network segmentation between engagements.
People
Every engineer is a salaried employee under an individual confidentiality agreement. Background checks appropriate to the engagement. Security training at onboarding and annually. No contractors and no gig platforms.
Software supply chain
Dependency scanning in CI, SBOM on request, pinned versions, and a documented process for responding to a disclosed vulnerability in something we shipped you.
Incident response
Documented runbook with named owners. Notification to affected clients without undue delay, and within contractual timelines where they're stricter. For financial services clients we operate to DORA's four-hour and 24-hour clocks.
Business continuity
Documented and rehearsed. Key-person risk is addressed by pairing on every engagement, not by an org chart.
Sector-Specific
Built for the sector you're regulated in.
Healthcare
We operate as a Business Associate under a signed BAA. We build to the HIPAA Security Rule safeguards, and — anticipating the proposed 2025 Security Rule amendments — to a baseline of enforced MFA, encryption at rest and in transit, network segmentation, asset inventory, vulnerability scanning every six months, annual penetration testing, and ePHI restoration within 72 hours.
Financial services
PCI DSS v4.0.1–aligned architecture where cardholder data is in scope. DORA Article 30 contractual terms, a Register of Information data pack including the full subcontracting chain, documented exit provisions, and incident reporting aligned to DORA timelines.
EU personal data
GDPR-aligned processing, standard contractual clauses for transfers, a signed DPA available before engagement, and a published subprocessor list with change notification.
What we don't claim. Explicitly.
- Not "HIPAA certified." No such credential exists — HHS does not certify any person or product as HIPAA compliant.
- Not "PCI DSS certified" as a development firm. We build systems that pass PCI DSS assessments; that's a different sentence and it's the accurate one.
- Not "DORA compliant" or "DORA certified." DORA compliance is the financial entity's obligation and no certification scheme exists.
- Not "EU AI Act compliant." Compliance attaches per AI system and requires conformity assessment. An ISO/IEC 42001 certificate does not confer it.
- Not FDA cleared. Clearance attaches to a device and is held by its manufacturer. We build to IEC 62304 and support sponsors through submissions.
- Not HITRUST certified unless and until we hold a validated assessment at a named tier, in which case this page will name the tier.
Independence
No AI lab, model provider or cloud vendor holds equity or board representation. Your data isn't training anything of ours. Neutrality is structural, not a policy.
Independence StatementHow we employ
Everyone who touches your data is on our payroll. Not contractors, not a gig platform, not an annotation marketplace — salaried employees in Vietnam, with names we'll give you before an engagement starts.
How We EmploySubprocessors
Every third party in the chain, published with data locations and DPAs — plus the sub-subprocessor level, because DORA asks for it. 30-day change notification.
Subprocessor ListSend us your vendor questionnaire.
We'll complete it before the first technical call. Contact nick.nguyen@syncsoftvn.com for anything not covered here.