SOC2C

Is this your company? Buyers are checking Synthesia here. Claim synthesia.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Synthesia logo

Synthesia

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Synthesia is SOC 2 Type II compliant. Synthesia also holds ISO 42001, ISO 27001, ISO 27701, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Synthesia allows you to create videos directly in a web browser. Simply select an actor, type in the text and use AI to generate your video without the need for actors, film crew or expensive equipment and post-production. You can create stunning business videos in minutes. As a company pioneering this new kind of media, we’re aware of the responsibility we have. It is clear to us that artificial intelligence and similarly powerful technologies cannot be built with ethics and security as an afterthought. They need to be front and centre and an integral part of the company. This is reflected in

Compliance & infrastructure

ISO 42001ISO 27001ISO 27701SOC 2 Type IIGDPR
Data handled
Video data of a person to create a custom avatarVoice audio data of a person to create a custom voiceIncidental PII as part of video scriptsMusic and image assets uploaded as part of the video generation processEmployee personally identifiable information (name, email address, IP address)

Documents

3

Compliance leadership

The person who leads Synthesia's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Synthesia's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

SynthesiaDec 2025

We’re proud to announce that Synthesia has successfully achieved ISO/IEC 27701:2019 certification — the leading international standard for Privacy Information Management Systems (PIMS). This certification confirms that our controls for handling and protecting personal data meet rigorous global requirements for both PII Controllers and PII Processors, as validated by A-LIGN with zero nonconformities during the Stage 2 audit. ISO 27701 extends our existing ISO/IEC 27001 Information Security Management System and demonstrates our mature, end-to-end governance of privacy across all processes involved in the secure and privacy-respecting development, delivery, and operation of Synthesia’s AI-driven video platform. The certification scope includes all assets, technologies, personnel, and business processes supporting our platform, including the responsible development and use of AI systems for avatar creation and voice cloning . This achievement builds on our existing ISO/IEC 27001 and ISO/IEC 42001 certifications, reinforcing Synthesia’s ongoing commitment to continuous improvement, transparency, and the highest standards of security and privacy. Customers can rely on Synthesia to safeguard personal data with independently verified controls aligned with international best practices.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Synthesia SOC 2 compliant?
Synthesia is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Synthesia ISO 42001 certified?
According to Synthesia's public trust center, Synthesia is ISO 42001 certified. On SOC2C this listing is Listed.
Is Synthesia ISO 27001 certified?
According to Synthesia's public trust center, Synthesia is ISO 27001 certified. On SOC2C this listing is Listed.
Is Synthesia ISO 27701 certified?
According to Synthesia's public trust center, Synthesia is ISO 27701 certified. On SOC2C this listing is Listed.
Is Synthesia GDPR compliant?
According to Synthesia's public trust center, Synthesia is GDPR compliant. On SOC2C this listing is Listed.

Answers published by Synthesia

Reproduced from Synthesia's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you support Single Sign-On (SSO)?
Yes, we support SAML 2.0 based SSO (With SCIM Bridge and JiT provisioning) and authentication via Google for corporate customers above a certain deal value. Please reach out to our sales team to discuss specifics.
Where is your data stored?
Storage and processing is performed within the cloud infrastructure provided by Amazon Web Services (AWS). Data is stored within the EU in data-centres based in Ireland. Operational backups are also stored in Ireland, secondary backups are stored in the AWS Frankfurt region. Storage facilities use multiple availability zones, each with redundant power and networking, and each physically separated by a number of miles. Relevant Transfer Impact Assessment details are shared under https://security.synthesia.io/documents
Will any of the data be shared with any third parties (e.g., sub-processors) at any point?
We use third-party cloud services as part of our service delivery. All third party service providers are evaluated within Legal, Security, Functionality and Commercial aspects. From a legal perspective, compliance with GDPR and other regulatory standards is a must, as well as compliance with requirements put on us by our customers. From a security perspective, we require SOC2 or ISO27001 as a rule. Exceptions can be made, upon answering a relevant security questionnaire, which is then reviewed and discussed. Third-party services functioning as sub-processors are listed in our Data Processing Agreement: https://www.synthesia.io/terms/data-processing-agreement and https://www.synthesia.io/legal/subprocessors Note that the list of third parties is subject to change, as the service evolves.
What encryption methods and processes are used to protect data in-transit or at-rest?
All communication is encrypted in-transit using TLS 1.2+. Data stored in our infrastructure is protected at-rest using the 256-bit Advanced Encryption Standard (AES-256) with encryption keys stored within the Amazon Key Management Service. Encryption keys are managed via AWS Key Management Service (KMS). AWS KMS uses hardware security modules (HSMs) that have been validated under FIPS 140-2. The access to KMS is controlled via IAM Access controls, and only enabled for selected employees. AWS KMS is designed so that no one, including AWS employees, can retrieve the plaintext KMS keys from the service. We do not support customer specific encryption keys.
What types of data do you collect/process?
We require name, email address and communication preferences to provide the service, which we obtain during sign-up. Music and image assets can be uploaded as part of the video generation process. To create a video on the platform you enter a text script, the script is then converted to a voice for an avatar to present the information in a video. To use a custom avatar for our platform, we require video data of an actor to create the avatar. For custom voices, we likewise require voice data.We also collect and process data for the legitimate interest of improving the service delivery and to meet legal obligations. Where additional services are offered we seek user consent. This is set out in our Terms of Service and the incorporated Data Processing Agreement.

Business & Industrial peers that completed SOC 2