Trust · Security & Compliance

What we're certified for, and what we're not.

Most vendor security pages are a wall of logos. This one is a list of what we hold, a description of how we actually operate, and an explicit list of things we don't claim. Ask for any of the underlying documents and we'll send them.

Certifications

Nothing held yet. Everything in progress, said plainly.

ISO/IEC 27001 — in progressInformation security management system — we operate to its controls today; certification audit underway
ISO 9001 · 27701 · 20000-1 — in progressQuality · privacy · IT service management — operating to these standards; audits scheduled
SOC 2 Type II — in progressObservation window underway — this row will state the criteria and period when the report exists
ISO/IEC 42001:2023 — in progressAI management system

No certification is displayed as held until the report or certificate exists — every row above is work in progress, and the section below describes how we operate in the meantime. Audit evidence to date is available under NDA.

Security Posture

How we operate, independent of any certificate.

Where your data lives

In your cloud tenancy, under your account, in the region you choose. We do not copy production data to Vietnam. Where an engagement requires us to hold data, it stays in the region you specify and is deleted on completion with written confirmation.

Access control

Role-scoped per engagement, least privilege, MFA enforced without exception, sessions logged. Access granted at engagement start and revoked at engagement end through a documented process, not by memory.

Encryption

At rest and in transit, using your key management where you have it. TLS 1.2 minimum, 1.3 preferred.

Endpoints and network

Managed devices with disk encryption, EDR and enforced patching. No engagement work on personal machines. Network segmentation between engagements.

People

Every engineer is a salaried employee under an individual confidentiality agreement. Background checks appropriate to the engagement. Security training at onboarding and annually. No contractors and no gig platforms.

Software supply chain

Dependency scanning in CI, SBOM on request, pinned versions, and a documented process for responding to a disclosed vulnerability in something we shipped you.

Incident response

Documented runbook with named owners. Notification to affected clients without undue delay, and within contractual timelines where they're stricter. For financial services clients we operate to DORA's four-hour and 24-hour clocks.

Business continuity

Documented and rehearsed. Key-person risk is addressed by pairing on every engagement, not by an org chart.

Sector-Specific

Built for the sector you're regulated in.

Healthcare

We operate as a Business Associate under a signed BAA. We build to the HIPAA Security Rule safeguards, and — anticipating the proposed 2025 Security Rule amendments — to a baseline of enforced MFA, encryption at rest and in transit, network segmentation, asset inventory, vulnerability scanning every six months, annual penetration testing, and ePHI restoration within 72 hours.

Financial services

PCI DSS v4.0.1–aligned architecture where cardholder data is in scope. DORA Article 30 contractual terms, a Register of Information data pack including the full subcontracting chain, documented exit provisions, and incident reporting aligned to DORA timelines.

EU personal data

GDPR-aligned processing, standard contractual clauses for transfers, a signed DPA available before engagement, and a published subprocessor list with change notification.

What we don't claim. Explicitly.

  • Not "HIPAA certified." No such credential exists — HHS does not certify any person or product as HIPAA compliant.
  • Not "PCI DSS certified" as a development firm. We build systems that pass PCI DSS assessments; that's a different sentence and it's the accurate one.
  • Not "DORA compliant" or "DORA certified." DORA compliance is the financial entity's obligation and no certification scheme exists.
  • Not "EU AI Act compliant." Compliance attaches per AI system and requires conformity assessment. An ISO/IEC 42001 certificate does not confer it.
  • Not FDA cleared. Clearance attaches to a device and is held by its manufacturer. We build to IEC 62304 and support sponsors through submissions.
  • Not HITRUST certified unless and until we hold a validated assessment at a named tier, in which case this page will name the tier.

Independence

No AI lab, model provider or cloud vendor holds equity or board representation. Your data isn't training anything of ours. Neutrality is structural, not a policy.

Independence Statement

How we employ

Everyone who touches your data is on our payroll. Not contractors, not a gig platform, not an annotation marketplace — salaried employees in Vietnam, with names we'll give you before an engagement starts.

How We Employ

Subprocessors

Every third party in the chain, published with data locations and DPAs — plus the sub-subprocessor level, because DORA asks for it. 30-day change notification.

Subprocessor List

Send us your vendor questionnaire.

We'll complete it before the first technical call. Contact nick.nguyen@syncsoftvn.com for anything not covered here.