Security

We sell vulnerability handling. It would be embarrassing to be bad at it.

Your firmware

Uploads travel over TLS and are analysed inside a per-scan temporary directory that is destroyed when the job finishes. We keep the component list and the evidence, not your image. Upload authorisation is a short-lived signed token bound to a single scan, so the analysis endpoint is not an open service.

Your evidence

Encrypted at rest and in transit. Retention is ten years per product, enforced as a stored retention date on every row rather than a convention someone has to remember. You can export everything in open formats at any time, including after cancelling.

The audit log

Case events are appended to a hash chain. The database refuses updates and deletes on that table outright. The one exception is an authorised erasure path used for account deletion and data subject requests, which is explicit, transactional and logged.

Payments

Processed by Dodo Payments as merchant of record. We never see or store card details.

Reporting a vulnerability to us

Email hello@synthworx.com with "security" in the subject. We aim to acknowledge within two working days and will tell you honestly what we can and cannot fix quickly. We do not run a bug bounty and we will not threaten you for reporting something in good faith.

Our own contact details are served at /.well-known/security.txt, the same way we tell customers to serve theirs.

Where data lives

Application and database are hosted in the United States. If EU data residency is a contractual requirement for you, tell us before you buy rather than after.