Platform Security | Synack

Security

Platform Security Overview

At Synack not only have we built a world-class Penetration Testing as a Service (PTaaS) Platform that’s instilled security from the very beginning. But we’ve taken the best aspects of security and compliance and melded them into a robust program. This is evident with how we handle sensitive customer data, manage upgrades, patch management, code releases. Our operational security practices incorporate frameworks such as OWASP, CREST, ISO 27001, and FedRAMP Moderate.

Certifications & Third-Party Attestations

ISO 27001:2022 is a framework with standardized requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within an organization. The goal of an ISMS based on ISO 27001 is to help organizations manage and protect their information assets, ensuring confidentiality, integrity, and availability.

FedRAMP Moderate is a U.S. Government program representing a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. It establishes a baseline of security controls for cloud services that handle personally identifiable information (PII) and sensitive but unclassified (SBU) information.Cloud Service Providers (CSPs) with FedRAMP Moderate authorization must implement 323 security controls defined by NIST Special Publication (SP) 800-53.

TX-RAMP Level 2 is a Texas Department of Information Resources (DIR) initiative. It establishes standardized security assessment, authorization, and continuous monitoring requirements for cloud services used by Texas state agencies and higher education institutions.  It applies to cloud computing services as defined by Texas Government Code, Section 2054.0593(a).

IASME Cyber Essentials is a UK government-backed cybersecurity certification scheme designed to help organizations of all sizes protect themselves against common cyber threats. IASME (Information Assurance for Small and Medium Enterprises) is one of the National Cyber Security Centre’s (NCSC) official delivery partners for the Cyber Essentials scheme. It centers around five key security controls that, when implemented correctly, can prevent a large percentage of cyber attacks.

CREST is an international not-for-profit accreditation and certification body that represents and supports the technical information security industry.  Service providers have to meet rigorous standards for business processes, data security, and testing methodologies. This gives clients assurance that they are working with a reputable and competent organization.

Privacy Shield Synack complies with the U.S.-E.U. and U.S.-Swiss Privacy Shield frameworks as set forth by the U.S. Department of Commerce. These frameworks govern the collection, use, and retention of personal data from the European Union and Switzerland.

Trust Center

Synack has established a Trust Center that further solidifies Synack’s commitment to our customers of transparency, trust and leading change within the cybersecurity industry. You can quickly pull-down policies, procedures, certificates, questionnaires and any other security and compliance related information.

Responsible Disclosure

To report a security vulnerability, please visit https://www.synack.com/vdp/synack/.

A successful submission may result in an invitation to join the Synack Red Team.