Security
Built to hold other people’s users.
Synq holds your users’ identities and signs the tokens your apps trust. These are the rules its code follows. Each one is built and tested today.
Tenants never see each other
Every row that belongs to a tenant carries its org or brand, and rows point at each other only through keys that include it, so Postgres itself refuses a reference into another tenant’s data. Every query is scoped by the tenant the request signed in as, never by a value in the request. Each issuer has its own cookies, so tenants never share a session.
Strict protocol defaults
The authorization code flow with PKCE (S256) on every request, redirect URIs matched exactly, codes that work once, and refresh tokens that rotate on every use. A code or refresh token presented a second time revokes the whole grant. There are no wildcards and no exceptions, for Aerosol’s own apps either.
Tokens meant for one API
Access tokens are JWTs for a single API that live 5 to 15 minutes. An app asking for a scope it may not have is refused, never silently trimmed. Only the app a token was issued to can revoke it, and only that app or the API the token is for can introspect it.
No secret stored in the clear
App secrets and API keys are shown once and stored only as hashes. Passwords are hashed with Argon2id. Signing keys and webhook secrets are encrypted with AES-256-GCM under a key kept outside the database, so a copy of the database alone opens nothing.
Keys that rotate on a schedule
Each brand’s signing key is published a day before it signs, signs for 90 days, and stays published a day after it retires, when its private half is erased. Apps that cache keys never see a token they can’t verify.
Passwords handled with care
New passwords are checked against known breaches unless a brand turns the check off, with only five characters of a hash ever leaving Synq. Wrong guesses are slowed down and then locked out, and every refusal reads and takes the same, so nobody can tell which addresses have accounts.
Rate limits everywhere it matters
Sign-in pages, token endpoints and the management API are limited per address, per app and per account, with the counts shared by every server.
Nothing sensitive in logs
Requests are logged by route, never with their query strings, headers or bodies. Tokens, codes, cookies, passwords and keys never reach a log, a trace or an error message, and a redaction layer catches anything that slips through.
Webhooks you can verify
Deliveries are signed over their id, time and body following the Standard Webhooks scheme, so your endpoint can check each one and turn away a captured delivery sent again later. Synq refuses to deliver to private network addresses.
Every change on the record
Every change your team, your API keys or Synq makes is recorded in your audit log with who made it and from where, in the same transaction as the change itself.
Not done yet
What we can’t claim yet.
Synq has not had an independent security audit or penetration test, and it holds no certification such as SOC 2 or ISO 27001.
Its issuers have not yet been through the OpenID Foundation’s conformance suite. Running that suite against Synq on every change is part of the first release.
Found a vulnerability?
Please tell us privately first. The disclosure policy says what to send and what we commit to.