Security and compliance

Built secure, by design

From encrypted credentials to role-based access and full audit trails, security is engineered into every layer of SyncXpress.

Authentication

  • MFA
  • SSO
  • OAuth / OIDC
  • SAML 2.0
  • Secure session management

Authorisation

  • Role-based access control
  • Least privilege
  • Integration-level permissions
  • Environment-level permissions

Data security

  • TLS in transit
  • Encryption at rest
  • Encrypted credentials
  • Secret masking
  • No credentials in logs

API security

  • OAuth 2.0
  • API keys
  • Rate limiting
  • Request validation
  • IP restrictions
  • Audit logging
Credential management

Secrets never exposed

Credentials are stored separately from integration configuration, encrypted at rest, and never displayed in plaintext after saving.

  • Encrypted credential storage
  • Secret rotation and expiry notifications
  • Least-privilege access
  • Audit of every credential change
  • Optional external secrets manager

Supported authentication methods

  • Username / password
  • OAuth 2.0
  • API key
  • Client certificate
  • Basic auth
  • Windows / integrated
  • Service account
  • Token-based
Role-based access

Six default roles, fully configurable

Default SyncXpress roles and their capabilities
RoleCapabilities
Super AdminFull platform administration
AdminManage integrations, connections and users
Integration ManagerCreate and manage integrations
OperatorExecute and monitor integrations
AuditorView executions and audit logs
ViewerRead-only dashboard access
Data privacy

GDPR-ready by design

SyncXpress may process personal, HR and access-control data — so privacy controls are built in for UK GDPR and EU GDPR deployments.

Configurable retention

Define how long processed data and logs are kept per integration.

Data export and deletion

Export or delete data to meet subject-access and erasure requests.

Sensitive-field masking

Mask personal, HR and access-control fields in logs and the console.

Tenant isolation

A multi-tenant architecture keeps each organisation’s data separate.

Disaster recovery

  • Automated database backups
  • Configuration and integration backups
  • Documented recovery procedures
  • Continuous monitoring
  • Configurable RPO and RTO by service tier
Resilience

Recoverable and resilient

Automated backups, configuration snapshots and documented recovery procedures keep your integrations and data safe — with RPO and RTO configurable per service tier.