synthetic cfo

Security

Last updated: 24 August 2026

This page answers the questions security reviewers ask, in plain language and without overstatement. synthetic cfo is operated by a single founder and this page says exactly what is and is not in place. Nothing here is aspirational.

The data itself carries no risk

What we store about you

How the service is protected

Backups and continuity

Deletion and retention

A signable data processing agreement

Customers on a paid plan who need a signed DPA for vendor onboarding can read the full text at app.syntheticcfo.com/dpa. It commits to exactly what this page describes, names the sub-processors the Privacy Policy discloses, and is executed by email with both parties' legal details completed at signature.

What we do not claim

We hold no SOC 2 or ISO 27001 certification and we will not pretend otherwise. This is a young product run with care by one person, and the honest summary of its security posture is this: the sensitive thing most services must protect, real customer data, structurally does not exist here, and everything we do store is listed above.

Reporting a vulnerability

If you find a security issue, email us and you will get a human reply. We ask for reasonable disclosure time and we will credit you if you want credit.

← Back to synthetic cfo