Security 🔒
Our customers' trust and data security are core and critical to what we do at SaaSync.
Overview
SaaSync was built with data security as a central consideration in our architecture. SaaSync limits the storage of Customer Data on our servers. Our mission is to transfer Customer Data securely from one system to another while storing only the data reasonably necessary to provide and support the Services.
We have implemented administrative, technical, and organizational safeguards designed to protect Customer Data based on the nature of the data and the risks presented. Some of those safeguards and data-handling practices are described below.
Data storage
SaaSync limits the storage of Customer Data on our servers for most of our integration data sources by acting as a real-time translation layer between the integration source and destination.
For all data sources, for performance reasons and to reduce API rate-limit exceptions, we may cache some Customer Data for up to one hour, at which time the cache is cleared. We may also log error responses from source or destination systems for up to 30 days, maintain an audit trail of actions performed for up to 60 days, and retain a history of received webhooks for up to 30 days for systems that enable webhooks. Error responses and webhook payloads may contain Customer Data. Access to these records is restricted to authorized personnel who require it to operate, secure, or support the Services.
For QuickBooks Online and Xero data sources only, due to the nature of how our integrations function, SaaSync stores data associated with Invoices, Credit Notes/Memos, and Sales Receipts/Receive Money Transactions, if enabled. SaaSync also stores a limited set of Customer and Product data for identification and classification purposes. For certain classification functions, SaaSync may send limited invoice-line fields to an authorized artificial-intelligence subprocessor, as described in our Subprocessor List.
For Paddle and Shopify Partners data sources only, due to API design limitations, including restrictive rate limits, SaaSync retains received webhook history for as long as the applicable connection or account remains active.
If a Customer expressly deletes a data-source connection or account, the associated active data is queued for deletion from production systems and is ordinarily deleted within minutes. Residual copies may remain in encrypted backups for up to seven days and remain protected until deleted through the ordinary backup lifecycle.
When a Customer’s subscription becomes inactive because a trial expires, the Customer cancels, payment is not made, or the Services otherwise end without an express deletion request, SaaSync retains the applicable production data for up to 60 days to permit reactivation or export. SaaSync ordinarily notifies the Customer approximately ten days before scheduled deletion. At the end of that period, the data is queued for deletion from production systems. Residual copies may remain in encrypted backups for up to seven additional days and remain protected until deleted through the ordinary backup lifecycle.
SaaSync’s primary application infrastructure and covered Customer Data at rest are hosted in the United States. Authorized subprocessors may process Customer Data in the United States and other locations described in our Subprocessor List.
Data privacy
As between SaaSync and the Customer, Customer Data remains the Customer's data. SaaSync does not sell Customer Data or share Customer Data with third parties for cross-context behavioral advertising or targeted advertising. SaaSync uses Customer Data only to provide, secure, maintain, and support the Services, as otherwise instructed by the Customer, or as permitted by the applicable agreement and law.
- Data protection: Where applicable, SaaSync processes Customer Personal Data in accordance with its Data Processing Addendum and uses contractual transfer safeguards described there. SaaSync requires subprocessors that process Customer Personal Data to enter into agreements containing applicable data-protection obligations.
- Credit cards: SaaSync does not process or store any credit card details belonging to you or your customers. Card details are never transmitted through or stored on our infrastructure. All credit card payments made to SaaSync for the Service go through our partner, Stripe. Details about their security and PCI compliance can be found at Stripe’s security page.
- Passwords: SaaSync does not store user passwords in readable form. Passwords are salted and hashed using bcrypt, a password-based key-derivation function. Customers and users are responsible for choosing strong, unique passwords and protecting their credentials. Two-factor authentication is available to SaaSync users, and SaaSync strongly recommends enabling it.
Product & Network security
- Password and Credential Storage: User passwords are salted and hashed using bcrypt. Integration API credentials are encrypted at rest using an industry-standard encryption algorithm.
- Two-factor authentication (2FA): Two-factor authentication is available to SaaSync users, and SaaSync strongly recommends enabling it.
- Uptime: Current and historical service-availability information is available at https://status.saasync.com.
- Monitoring: We monitor application, software, and infrastructure behavior using established monitoring and alerting services.
- Data hosting and storage: SaaSync's primary application infrastructure and covered Customer Data at rest are hosted in Amazon Web Services facilities in the United States. Authorized subprocessors may process Customer Data in additional locations identified in our Subprocessor List.
- Resilience: SaaSync uses redundant infrastructure and backup or recovery mechanisms designed to reduce the risk of service interruption and support restoration following an incident.
- Encryption: SaaSync protects data in transit using industry-standard TLS and encrypts sensitive data at rest using industry-standard encryption.
- Network security: SaaSync's primary application servers operate within a logically isolated cloud network with network-access controls designed to restrict unauthorized access to internal resources.
- Vulnerability management: SaaSync performs vulnerability scanning and engages qualified third parties to conduct penetration testing of the SaaSync application and infrastructure. Identified findings are assessed and remediated according to risk.
- Incident response: SaaSync maintains a documented incident-response process that includes investigation, containment, remediation, internal escalation, and post-incident review. SaaSync notifies affected Customers of qualifying Security Incidents in accordance with its Data Processing Addendum and applicable law.
- Access controls: Access to production systems and Customer Data is limited to authorized personnel with a business need. Access rights are reviewed periodically and removed when no longer required. Privileged access is protected using multifactor authentication.
- Change and patch management: SaaSync maintains processes for reviewing and deploying changes and for applying security updates based on risk.
- Backup and recovery: SaaSync maintains encrypted backups and recovery procedures designed to restore availability following a technical incident. Recovery procedures are tested periodically.
Data centers and network
Amazon Web Services maintains security and privacy certifications and assurance reports applicable to its cloud services, including ISO 27001 and SOC reports. The availability and scope of particular certifications depend on the AWS services and regions used. These certifications support SaaSync's vendor assessment but do not, by themselves, establish SaaSync's compliance with any particular law.