We take security seriously. From encryption to access controls, every layer of SyncAuction is designed to protect your business.
Comprehensive protection for your credentials and data
All stored data, including your API credentials, is encrypted using AES-256 encryption. Your secrets are never stored in plain text.
All data transmitted between your browser, our servers, and third-party APIs is protected with TLS 1.3 encryption.
Each organization has its own encryption key. Your data is isolated and cannot be accessed by other tenants.
Protect your account with 2FA using authenticator apps like Google Authenticator or Authy.
Enterprise customers can integrate with their identity provider for single sign-on access.
Every action is logged with timestamps and user attribution. Review who did what and when.
We're committed to meeting the highest security standards and compliance requirements for our customers.
Full compliance with EU data protection regulations
California Consumer Privacy Act compliance
Working toward SOC 2 Type II certification
Hosted on AWS with SOC 2 certified infrastructure
Data deleted within 90 days of account termination
Export your data anytime in standard formats
Automated backups with point-in-time recovery
Trusted by dealers who prioritize security
Your data is hosted on world-class infrastructure with multiple layers of physical and logical security.
Hosted on AWS with SOC 1, SOC 2, and ISO 27001 certified data centers
Primary infrastructure in US-East region with automatic failover
Daily encrypted backups with 30-day retention and point-in-time recovery
Cloudflare enterprise protection against distributed denial-of-service attacks
How we handle security events to protect your business
24/7 automated monitoring detects anomalies and potential security events in real-time.
Security team assesses severity, scope, and potential impact within 15 minutes.
Immediate actions to contain the incident and prevent further impact.
Full remediation, customer notification (if required), and post-incident review.
In the event of a security incident affecting your data, we will notify you within 72 hours via email and dashboard notification, in compliance with GDPR requirements.
Built for enterprise reliability
Control who can access what in your organization
Full access to all features, billing, and team management
Manage stores, sync settings, and team members
Edit products, pricing rules, and view reports
Read-only access to dashboards and reports
We take security seriously. If you discover a vulnerability, please report it responsibly. We appreciate your help in keeping SyncAuction secure.
Common questions about our security practices
Your API credentials are encrypted using AES-256 encryption with per-tenant keys. They are never stored in plain text and are only decrypted in memory when needed for sync operations.
No. Your data is completely isolated using per-tenant encryption keys and separate database schemas. There is no data sharing between customers.
Upon account cancellation, all your data including API credentials, sync history, and settings are permanently deleted within 90 days. You can request immediate deletion by contacting support.
Yes. SyncAuction is fully GDPR compliant. We process data based on legitimate business interest, provide data export on request, and honor deletion requests within 30 days.
We employ multiple layers of protection including two-factor authentication, role-based access controls, session management, and comprehensive audit logging of all account activities.
Our primary infrastructure is hosted on Amazon Web Services (AWS) in the US-East region. All data centers are SOC 1, SOC 2, and ISO 27001 certified with automatic failover capabilities.
Have more security questions?
Contact our security teamRequest our security whitepaper for a comprehensive overview of our security practices.
Request Security Whitepaper