Security & trust
How we handle payments, delivery links, and operational security for US business buyers.
Payments
- Checkout is hosted by Stripe. Card numbers are entered on Stripe’s pages — we never receive or store full PAN data.
- We store order metadata needed for fulfillment (email, product, status).
- Transport is HTTPS on the public storefront and admin console.
Digital delivery
- Download links are capability URLs with time-limited signed tokens after a paid order.
- Do not forward download links; request a re-send from support if needed.
- Commercial email includes unsubscribe; transactional purchase email is separate.
Operational controls
- Admin access requires a private token and signed session cookie.
- Security headers (CSP, HSTS, framing protections) are applied at the edge.
- Subprocessors for hosting, database, email, and payments are listed in the Privacy Policy.
We do not claim SOC 2 or ISO certification on this page. If your procurement process requires a questionnaire, email us.
Report a security issue
Email contact@synapticfour.com with a clear description and steps to reproduce. Please do not open a public GitHub issue for vulnerability reports.