Security requirements

How we approach security across your operations and systems.

We define access, data-handling, and review requirements around your systems and the work we agree to deliver. Controls and responsibilities are documented for each engagement.

Discuss This Service
Illustration of layered access, data, and review controls
Security requirements

Security practices within the agreed scope.

Access, data-handling, and review requirements form the baseline for each engagement. The technical controls used to meet them depend on the platform, configuration, and agreed scope.

Least-privilege access

We define required permissions, approval owners, access duration, and removal responsibilities for the work in scope.

Data handling

We define data-handling requirements, including encryption in transit and at rest. Implementation depends on the systems and configurations in scope.

Environment boundaries

Isolation requirements are defined around the work and data involved. Account, network, and storage separation depend on the platform and configuration.

Logging and accountability

Logging, monitoring, and alerts are scoped to the engagement and platform capabilities, with review responsibilities documented.

Human review where it matters

Sensitive actions require human approval where specified in the agreed workflow. Review requirements and responsibilities are documented.

Agreed responsibilities

Synotech leads security decisions and communication, with client approval for relevant changes according to their type and scope.

Where controls apply

Review the boundaries between systems.

Identity

  • Authentication and SSO options
  • Roles and permissions
  • Session settings

Application

  • Application code and settings
  • Input validation points
  • Secrets storage

Integration

  • Connector credentials
  • Endpoint restrictions
  • Platform rate limits

Data

  • Transfers and storage
  • Required data fields
  • Retention and deletion settings

Operations

  • Monitoring responsibilities
  • Change approvals
  • Incident communication
Illustrative operational workflow

From source data to a reviewed action.

Business data

Permitted records
Required fields
Approved sources

Rules + review

Validate inputs
Route exceptions
Request required approval

Approved action

Proceed after checks
Update the target system
Record the outcome

Shared responsibility

Separate provider controls from implementation work.

  • Review the provider’s documented controls and the services actually used.
  • Confirm which account, network, and application settings are in scope.
  • Assign responsibility for updates and dependency maintenance.
  • Agree incident contacts, escalation paths, and communication expectations.
AI safeguards

Review the AI workflow before use.

Confirm the provider, configuration, and review requirements for each use case. The diagram illustrates a possible flow.

User request
Retrieve from sources
AI processing
Validate + review
Approved response
  • Sources: identify permitted sources and the workflow’s access rights.
  • Provider data: list the prompts, records, and files sent to external AI services.
  • Retention and training: verify provider terms and applicable account or API settings.
  • Approval: specify which actions require a person’s authorization.
  • Fallback: define when uncertain output or failed validation should stop work or route it to review.
  • Activity logs: agree what is recorded, who can access it, and how long it is retained.
Illustrative human review

An exception that needs approval.

In this example, a payment to a new vendor is held for review because the amount exceeds the workflow’s approval threshold.

Illustrative approval workflow — sample data.
Sensitive exceptionRequires review
SystemFinance Ops
TypePayment approval
Amount$8,450.00
ReasonNew vendor + higher amount
Request changesApprove and continue

Display only — these controls do not initiate payments or change records.

Illustrative scene of a person reviewing an exception
Project requirements

Controls are tailored to your context.

Scope of work

Identify the workflows, systems, and operational responsibilities included in the engagement.

Data sensitivity

Identify the data involved, its sensitivity, and restrictions on its use or movement.

Platforms and integrations

Review platform capabilities, connected services, and the permissions each connection requires.

Requirements and responsibilities

We work with your team to identify relevant control requirements and agree the implementation scope.

For each requirement, agree the implementation owner, review authority, and scope before work begins.

FAQ

Practical security questions.

Review responsibilities and data-handling requirements before the engagement begins.

Synotech leads access decisions, with client approval according to the type and scope of the change. Access requirements, duration, and removal responsibilities are documented for the engagement.

Synotech leads security decisions and incident communication. Relevant changes require client approval according to their type and scope. Responsibilities are documented for the engagement; any response commitments need to be agreed within that scope.

Your data belongs to you. When the engagement ends, Synotech returns your data to you. Data-handling requirements are documented for the engagement; confirm the retention period and deletion schedule for the records involved.

Confirm the exact provider, service, account settings, data sent, and applicable retention or training terms for the proposed workflow.

Ask to discuss the proposed access, data-handling, and review requirements, and confirm what supporting material is available for the engagement.

Bring security into the design
from the start.

Discuss your access, data-handling, and review requirements alongside the work you need.

Start Free Health Check