Is this your company?Buyers are checking Synthesia here. Claim synthesia.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Synthesia allows you to create videos directly in a web browser. Simply select an actor, type in the text and use AI to generate your video without the need for actors, film crew or expensive equipment and post-production. You can create stunning business videos in minutes. As a company pioneering this new kind of media, we’re aware of the responsibility we have. It is clear to us that artificial intelligence and similarly powerful technologies cannot be built with ethics and security as an afterthought. They need to be front and centre and an integral part of the company. This is reflected in
Video data of a person to create a custom avatarVoice audio data of a person to create a custom voiceIncidental PII as part of video scriptsMusic and image assets uploaded as part of the video generation processEmployee personally identifiable information (name, email address, IP address)
We’re proud to announce that Synthesia has successfully achieved ISO/IEC 27701:2019 certification — the leading international standard for Privacy Information Management Systems (PIMS). This certification confirms that our controls for handling and protecting personal data meet rigorous global requirements for both PII Controllers and PII Processors, as validated by A-LIGN with zero nonconformities during the Stage 2 audit. ISO 27701 extends our existing ISO/IEC 27001 Information Security Management System and demonstrates our mature, end-to-end governance of privacy across all processes involved in the secure and privacy-respecting development, delivery, and operation of Synthesia’s AI-driven video platform. The certification scope includes all assets, technologies, personnel, and business processes supporting our platform, including the responsible development and use of AI systems for avatar creation and voice cloning . This achievement builds on our existing ISO/IEC 27001 and ISO/IEC 42001 certifications, reinforcing Synthesia’s ongoing commitment to continuous improvement, transparency, and the highest standards of security and privacy. Customers can rely on Synthesia to safeguard personal data with independently verified controls aligned with international best practices.
This listing is partial
5/11 details · 45%
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Synthesia SOC 2 compliant?
Synthesia is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Synthesia ISO 42001 certified?
According to Synthesia's public trust center, Synthesia is ISO 42001 certified. On SOC2C this listing is Listed.
Is Synthesia ISO 27001 certified?
According to Synthesia's public trust center, Synthesia is ISO 27001 certified. On SOC2C this listing is Listed.
Is Synthesia ISO 27701 certified?
According to Synthesia's public trust center, Synthesia is ISO 27701 certified. On SOC2C this listing is Listed.
Is Synthesia GDPR compliant?
According to Synthesia's public trust center, Synthesia is GDPR compliant. On SOC2C this listing is Listed.
Is Synthesia SOC 2 Type I or Type II?
Synthesia is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Synthesia's SOC 2 for a vendor risk assessment?
Yes. Synthesia's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Synthesia penetration tested?
Synthesia hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Synthesia secure?
Security isn't a single yes/no, but Synthesia is SOC 2 Type II compliant and holds ISO 42001, ISO 27001, ISO 27701, SOC 2 Type II, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Synthesia have a bug bounty or vulnerability disclosure program?
Synthesia hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@synthesia.io or via a /security page (Synthesia lists a security contact).
Who are Synthesia's subprocessors?
Synthesia's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Synthesia host or store data?
Synthesia's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Synthesia's trust center or security page?
Synthesia's trust center is at https://security.synthesia.io. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Do you support Single Sign-On (SSO)?
Yes, we support SAML 2.0 based SSO (With SCIM Bridge and JiT provisioning) and authentication via Google for corporate customers above a certain deal value. Please reach out to our sales team to discuss specifics.
Where is your data stored?
Storage and processing is performed within the cloud infrastructure provided by Amazon Web Services (AWS). Data is stored within the EU in data-centres based in Ireland. Operational backups are also stored in Ireland, secondary backups are stored in the AWS Frankfurt region. Storage facilities use multiple availability zones, each with redundant power and networking, and each physically separated by a number of miles. Relevant Transfer Impact Assessment details are shared under https://security.synthesia.io/documents
Will any of the data be shared with any third parties (e.g., sub-processors) at any point?
We use third-party cloud services as part of our service delivery. All third party service providers are evaluated within Legal, Security, Functionality and Commercial aspects. From a legal perspective, compliance with GDPR and other regulatory standards is a must, as well as compliance with requirements put on us by our customers. From a security perspective, we require SOC2 or ISO27001 as a rule. Exceptions can be made, upon answering a relevant security questionnaire, which is then reviewed and discussed. Third-party services functioning as sub-processors are listed in our Data Processing Agreement: https://www.synthesia.io/terms/data-processing-agreement and https://www.synthesia.io/legal/subprocessors Note that the list of third parties is subject to change, as the service evolves.
What encryption methods and processes are used to protect data in-transit or at-rest?
All communication is encrypted in-transit using TLS 1.2+. Data stored in our infrastructure is protected at-rest using the 256-bit Advanced Encryption Standard (AES-256) with encryption keys stored within the Amazon Key Management Service. Encryption keys are managed via AWS Key Management Service (KMS). AWS KMS uses hardware security modules (HSMs) that have been validated under FIPS 140-2. The access to KMS is controlled via IAM Access controls, and only enabled for selected employees. AWS KMS is designed so that no one, including AWS employees, can retrieve the plaintext KMS keys from the service. We do not support customer specific encryption keys.
What types of data do you collect/process?
We require name, email address and communication preferences to provide the service, which we obtain during sign-up. Music and image assets can be uploaded as part of the video generation process. To create a video on the platform you enter a text script, the script is then converted to a voice for an avatar to present the information in a video. To use a custom avatar for our platform, we require video data of an actor to create the avatar. For custom voices, we likewise require voice data.We also collect and process data for the legitimate interest of improving the service delivery and to meet legal obligations. Where additional services are offered we seek user consent. This is set out in our Terms of Service and the incorporated Data Processing Agreement.
Do you perform application security testing?
Security risk assessment is an integral part of our software development life cycle. We use frameworks such as OWASP Top 10, as part of the risk review. For development stories of a given size, complexity or sensitivity we perform a formal threat model analysis. The process is influenced by STRIDE, modified to better fit our team and processes. We use Semgrep to detect and manage code vulnerabilities (SAST, SCA and Container). We run weekly authenticated and un-authenticated DAST scans. We also have a strong partnership with HackerOne, with extensive application and network pentests, as well as a private bug bounty program. This means that everything we deploy is continuously pentested by vetted and experienced security researchers. We use Wiz.io to monitor for production infrastructure security issues such as vulnerabilities and misconfigurations
How do you secure access to data?
We ensure that all access is based on the principle of least privilege. We use an identity provider with built-in threat intelligence feeds (i.e. dark web monitoring), strong password complexity requirements and a requirement for all employees to use a FIDO2 compliant authentication factor (biometric or security key). All employees are required to use a password manager, with a unique strong password and multi-factor authentication by default for all accounts. Access to our cloud infrastructure has restricted permissions using role based access controls, with access alerts and auditing in place. For employee and contingent worker access to customer data and personal information we have implemented the following specific controls: * Written policy for limiting employee, contingent worker, and contractor access to sensitive data, such as role-based access limitations and use of the principle of least privilege * Periodic access reviews * Access requests and explicit approvals for all access to sensitive data * A requirement that all employees and contingent workers to execute NDA or other confidentiality agreements * Periodic privacy and security training * Immediate termination of access upon termination of employment * Physical access restrictions, such as key card access and video monitoring * Full audit logging of all access to our backend infrastructure and actions taken by staff
Do you have a Risk Assessment & Treatment process?
Risk assessment is an integral part of operating procedures and incorporated in our Risk Management Policy. This is implemented and monitored through Vanta, our compliance tracking platform. Within Vanta, we define risk areas, risk scenarios, treatments, etc. These are owned by relevant stakeholders within the business. The ISO, together with legal counsel, is responsible for overseeing this process. Controls and mitigatory measures are either continuously monitored for effectiveness through Vanta, with automated alerts for failures, or audited by ISO periodically as part of the general compliance upkeep. Controls related to SOC2 are also reviewed as part of the external audit.
What is the Security organisational structure within Synthesia?
Our Head of Security, Martin Tschammer (martin.tschammer@synthesia.io), is the Information Security Officer (ISO) for Synthesia, reporting to the CTO and senior management team. The roles and responsibilities at Synthesia are set out in our policy on Information Security Roles and Responsibilities.
Are you GDPR compliant?
We have a Data Privacy and GDPR Compliance Policy in place to meet our obligations under the UK Data Protection Act 2018, the UK's implementation of the General Data Protection Regulation (GDPR). We also have an explicit Data Subject Request Policy in place, which sets out how to respond to an individual’s request to exercise their rights under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. Further, Synthesia's Data Management Policy ensures that information is classified, protected, retained and securely disposed of in accordance to regulatory responsibilities as well as internal classification. Data Protection Impact Assessment and Transfer Impact Assessment have been conducted, and are shared on https://security.synthesia.io/documents
What security controls do you have implemented?
You can see a selection of Vanta-monitored security controls on the security portal (https://security.synthesia.io). You can also find a SIG Lite questionnaire and a Consensus Assessment Initiative Questionnaire (CAIQ)v4 under https://security.synthesia.io/documents for more details. In general, our control fabric is aligned with our policies, risk management program and industry best practices and standards. We secure access to all our systems and ensure that all access is based on the principle of least privilege. All employees are required to use a password manager, with a unique strong password and multi-factor authentication by default for all accounts. For employees, we use Okta as our identity management solution. For all Okta users, we require a FIDO2 compliant authentication factor (biometric or Yubico Security Key). Access to our cloud infrastructure has restricted permissions using role based access controls, with access alerts and auditing in place. Encryption, audit logging, password policy etc are in place, as evidenced on this Trust Report. We have a centralised MDR/SOC function that is able to detect and respond to incidents coming from workstations, servers, cloud infrastructure and identity management platform 24/7. Our infrastructure is secured using internal networks protected by virtual firewalls. Access to the network configuration is restricted and only allowed on the basis of least privilege. We use AWS to provide the infrastructure for our production system. We review our infrastructure with external security experts at least annually to ensure we meet best practises and identify areas that need to be addressed.
How do you notify customers in case of a security incident or breach?
We have well-established Incident Response playbooks. For incidents where Synthesia is the Data Controller, regulatory authorities and affected individual will be notified without undue delay, but in no later than within 72 hours. For incidents where Synthesia is the Data Processor, Synthesia will notify the Data Controller as stipulated in the applicable DPA. Incident response and disaster recovery plans are tested annually.