Trust Center - Synthesia
Synthesia
Synthesia allows you to create videos directly in a web browser. Simply select an actor, type in the text and use AI to generate your video without the need for actors, film crew or expensive equipment and post-production. You can create stunning business videos in minutes.
FAQ
Do you support Single Sign-On (SSO)?
Yes, we support SAML 2.0 based SSO (With SCIM Bridge and JiT provisioning) and authentication via Google for corporate customers above a certain deal value. Please reach out to our sales team to discuss specifics.
Where is your data stored?
Storage and processing is performed within the cloud infrastructure provided by Amazon Web Services (AWS). Data is stored within the EU in data-centres based in Ireland. Operational backups are also stored in Ireland, secondary backups are stored in the AWS Frankfurt region. Storage facilities use multiple availability zones, each with redundant power and networking, and each physically separated by a number of miles. Relevant Transfer Impact Assessment details are shared under https://security.synthesia.io/documents
Will any of the data be shared with any third parties (e.g., sub-processors) at any point?
We use third-party cloud services as part of our service delivery. All third party service providers are evaluated within Legal, Security, Functionality and Commercial aspects. From a legal perspective, compliance with GDPR and other regulatory standards is a must, as well as compliance with requirements put on us by our customers. From a security perspective, we require SOC2 or ISO27001 as a rule. Exceptions can be made, upon answering a relevant security questionnaire, which is then reviewed and discussed. Third-party services functioning as sub-processors are listed in our Data Processing Agreement: https://www.synthesia.io/terms/data-processing-agreement and https://www.synthesia.io/legal/subprocessors
What encryption methods and processes are used to protect data in-transit or at-rest?
All communication is encrypted in-transit using TLS 1.2+.
Data stored in our infrastructure is protected at-rest using the 256-bit Advanced Encryption Standard (AES-256) with encryption keys stored within the Amazon Key Management Service.
Encryption keys are managed via AWS Key Management Service (KMS). AWS KMS uses hardware security modules (HSMs) that have been validated under FIPS 140-2. The access to KMS is controlled via IAM Access controls, and only enabled for selected employees. AWS KMS is designed so that no one, including AWS employees, can retrieve the plaintext KMS keys from the service.
What types of data do you collect/process?
We require name, email address and communication preferences to provide the service, which we obtain during sign-up. Music and image assets can be uploaded as part of the video generation process. To create a video on the platform you enter a text script, the script is then converted to a voice for an avatar to present the information in a video. To use a custom avatar for our platform, we require video data of an actor to create the avatar. For custom voices, we likewise require voice data. We also collect and process data for the legitimate interest of improving the service delivery and to meet legal obligations. Where additional services are offered we seek user consent. This is set out in our Terms of Service and the incorporated Data Processing Agreement.
Do you perform application security testing?
Security risk assessment is an integral part of our software development life cycle. We use frameworks such as OWASP Top 10, as part of the risk review. For development stories of a given size, complexity or sensitivity we perform a formal threat model analysis. The process is influenced by STRIDE, modified to better fit our team and processes. We use Semgrep to detect and manage code vulnerabilities (SAST, SCA and Container). We run weekly authenticated and un-authenticated DAST scans. We also have a strong partnership with HackerOne, with extensive application and network pentests, as well as a private bug bounty program. This means that everything we deploy is continuously pentested by vetted and experienced security researchers. We use Wiz.io to monitor for production infrastructure security issues such as vulnerabilities and misconfigurations.
How do you secure access to data?
We ensure that all access is based on the principle of least privilege. We use an identity provider with built-in threat intelligence feeds (i.e. dark web monitoring), strong password complexity requirements and a requirement for all employees to use a FIDO2 compliant authentication factor (biometric or security key). All employees are required to use a password manager, with a unique strong password and multi-factor authentication by default for all accounts. Access to our cloud infrastructure has restricted permissions using role based access controls, with access alerts and auditing in place.
Do you have a Risk Assessment & Treatment process?
Risk assessment is an integral part of operating procedures and incorporated in our Risk Management Policy. This is implemented and monitored through Vanta, our compliance tracking platform. Within Vanta, we define risk areas, risk scenarios, treatments, etc. These are owned by relevant stakeholders within the business. The ISO, together with legal counsel, is responsible for overseeing this process. Controls and mitigatory measures are either continuously monitored for effectiveness through Vanta, with automated alerts for failures, or audited by ISO periodically as part of the general compliance upkeep. Controls related to SOC2 are also reviewed as part of the external audit.
What is the Security organisational structure within Synthesia?
Our Head of Security, Martin Tschammer (martin.tschammer@synthesia.io), is the Information Security Officer (ISO) for Synthesia, reporting to the CTO and senior management team. The roles and responsibilities at Synthesia are set out in our policy on Information Security Roles and Responsibilities.
Are you GDPR compliant?
We have a Data Privacy and GDPR Compliance Policy in place to meet our obligations under the UK Data Protection Act 2018, the UK's implementation of the General Data Protection Regulation (GDPR). We also have an explicit Data Subject Request Policy in place, which sets out how to respond to an individual’s request to exercise their rights under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. Further, Synthesia's Data Management Policy ensures that information is classified, protected, retained and securely disposed of in accordance to regulatory responsibilities as well as internal classification.
What security controls do you have implemented?
You can see a selection of Vanta-monitored security controls on the security portal (https://security.synthesia.io). You can also find a SIG Lite questionnaire and a Consensus Assessment Initiative Questionnaire (CAIQ)v4 under https://security.synthesia.io/documents for more details.
In general, our control fabric is aligned with our policies, risk management program and industry best practices and standards. We secure access to all our systems and ensure that all access is based on the principle of least privilege. All employees are required to use a password manager, with a unique strong password and multi-factor authentication by default for all accounts. For employees, we use Okta as our identity management solution. For all Okta users, we require a FIDO2 compliant authentication factor (biometric or Yubico Security Key). Access to our cloud infrastructure has restricted permissions using role based access controls, with access alerts and auditing in place. Encryption, audit logging, password policy etc are in place, as evidenced on this Trust Report. We have a centralised MDR/SOC function that is able to detect and respond to incidents coming from workstations, servers, cloud infrastructure and identity management platform 24/7. Our infrastructure is secured using internal networks protected by virtual firewalls. Access to the network configuration is restricted and only allowed on the basis of least privilege. We use AWS to provide the infrastructure for our production system. We review our infrastructure with external security experts at least annually to ensure we meet best practises and identify areas that need to be addressed.
How do you notify customers in case of a security incident or breach?
We have well-established Incident Response playbooks. For incidents where Synthesia is the Data Controller, regulatory authorities and affected individual will be notified without undue delay, but in no later than within 72 hours. For incidents where Synthesia is the Data Processor, Synthesia will notify the Data Controller as stipulated in the applicable DPA.
Incident response and disaster recovery plans are tested annually.
Do you have a Bug Bounty program?
We have a private bug bounty program, managed by HackerOne. Please feel free to submit any vulnerability reports to security@synthesia.io, and we will route you to the submission portal.