SynQBack to SynQ

Trust center

Controls you can inspect. Claims kept honest.

SynQ has implemented technical and product controls mapped to India privacy duties, HIPAA safeguards and SOC 2 trust criteria. This is a readiness statement, not a certification, legal determination, BAA, or independent audit report.

Privacy and India readiness

  • Purpose-specific consent records
  • Patient access, correction and deletion request tracking
  • Immutable access and administrative audit events
  • Role and clinic-tenant access boundaries

HIPAA safeguard mapping

  • Unique account and role access
  • Short-lived private document links
  • Recorded document access and integrity checks
  • Transmission protection and session controls

SOC 2 readiness

  • Security and release evidence register
  • Change, workflow and AI traceability
  • Availability and response-state monitoring
  • Human approval for sensitive clinical and AI actions

Clinical and AI safety

  • No-diagnosis boundary
  • Approved-version clinical publication
  • Emergency escalation wording
  • Policy filtering, redaction and citations

Independent evidence still required

HIPAA legal applicability and BAA decisions, a SOC 2 examination, independent penetration and accessibility assessments, breach exercises, and external malware-service assurance remain blocked until qualified third parties complete them. SynQ does not present these as passed.

Current document protection

Files are private, screened before use, opened with expiring links after a server-side ownership check, and each successful opening is written to access history.