Security

Security Policy

Overview of DataSync’s security program and customer commitments.

Last updated March 15, 2025 DataSync resources

Program overview

DataSync’s security program is built on layered technical controls, rigorous governance, and third-party audits. This policy summarizes the safeguards that protect customer data and the responsibilities shared between DataSync and customers.

Governance

  • Frameworks: DataSync is SOC 2 Type II audited annually and maintains HIPAA controls for applicable customers.
  • Policies: Security, access, change management, and incident response policies are reviewed at least annually.
  • Training: All employees complete security, privacy, and phishing training during onboarding and annually thereafter.

Technical controls

  • Encryption: Customer data is encrypted at rest using AES-256 and in transit using TLS 1.2+. AS2 and SFTP connections enforce mutual authentication.
  • Access management: Single sign-on (SSO), SCIM provisioning, least-privilege roles, and time-bound access approvals are enforced for internal tools and production systems.
  • Monitoring: Logs, metrics, and traces are streamed to a central SIEM with automated alerting, anomaly detection, and on-call escalation.

Application security

  • Secure development lifecycle practices include peer reviews, automated testing, dependency scanning, and regular penetration tests by independent firms.
  • All changes to production follow change-control procedures with rollback plans.

Incident response

  • DataSync maintains a 24/7 incident response team with documented playbooks.
  • Customers are notified promptly if their data is impacted, including details, remediation steps, and follow-up actions.

Business continuity

  • The platform operates in active-active regions with automated failover, backups, and disaster recovery drills.
  • Recovery point objective (RPO) is < 15 minutes; recovery time objective (RTO) is < 1 hour for critical services.

Customer responsibilities

  • Configure access controls (SSO, RBAC) according to organizational policies.
  • Keep contact information and escalation paths current.
  • Use supported encryption configurations for partner connections.

Contact

For security inquiries or to request additional documentation, email security@datasync.com.

Need a human?

Contact support@datasync.com for policy questions or visit the support center to open a ticket.