Security
SyncWise reads your sales data and writes to your accounting ledger. That is a lot of trust to ask for, so this page sets out plainly what we do to deserve it — and, at the bottom, what we do not yet have.
Your data stays in the UK
SyncWise runs on a single database hosted in London (AWS eu-west-2). Your invoice data is not copied to the US, and it is not moved between regions. If you need to tell your auditor or your DPO where the data physically lives, the answer is one country and one region.
Encrypted in transit and at rest
Every connection to SyncWise uses TLS. Everything stored — invoices, evidence documents, VAT decisions — is encrypted at rest by the underlying platform using AES-256. Nothing is written to disk in the clear.
We never hold your accounting password
Xero and QuickBooks connect over OAuth. You authorise SyncWise from inside your own accounting software, and we receive a token that you can revoke at any time from your side without contacting us. We never see, store or ask for your login.
One customer cannot see another
Separation is enforced in the database itself, not in the application code. Every table carries a tenant boundary that the database refuses to cross, and the public-facing keys are explicitly blocked from reading customer data at all. A bug in the interface cannot leak another company's invoices, because the interface is not what is holding the line.
Evidence you cannot quietly change
Every posting is logged against the source document it came from, together with the VAT decision that was applied and the rule that produced it. Those evidence records are append-only and protected against deletion for seven years, including from us. If HMRC asks why an invoice was treated the way it was, the answer is on record and it has not been edited after the fact.
Nothing posts on a guess
Where SyncWise cannot confirm something — a duplicate it is unsure about, a VAT treatment it cannot evidence, an accounting system that will not answer — it stops and asks a human rather than posting anyway. Failing safe is a design rule, not a fallback.
The short version
What we don't have yet
Plenty of software companies imply certifications they do not hold. We would rather you heard it from us.
SyncWise is not certified to ISO 27001 and has not completed a SOC 2 audit. We have not yet commissioned an independent penetration test. We are a small, focused company and those are expensive exercises that we intend to take on as we grow — but today they would be claims, not facts.
What we can offer instead is specifics. If your finance or IT team has a security questionnaire, send it and we will complete it honestly, including the questions where the answer is no.
Reporting a problem
If you believe you have found a vulnerability in SyncWise, please tell us before you tell anyone else. We will acknowledge your report within one business day and keep you updated until it is closed. We will not pursue anyone who reports a genuine issue in good faith.