Security
Security at SyncHive
Last updated: Jun 3, 2026
SyncHive is designed to help organisations connect, exchange, route, store, and manage data between systems, applications, and data stores. Because SyncHive handles customer data flows, security, privacy, and operational resilience are core to how we design and operate the platform.
This page summarises the security practices used by Meaningful Technology Ltd trading as SyncHive to protect customer data and operate the SyncHive service.
1. Security overview
SyncHive uses layered security controls across hosting, access management, encryption, monitoring, backups, incident response, and supplier management.
Our security approach is based on the following principles:
- protect customer data by design;
- limit access to systems and data based on need;
- encrypt data in transit and at rest;
- monitor the service for reliability, performance, and security;
- maintain backups for business continuity and disaster recovery;
- use trusted infrastructure and service providers;
- be transparent about subprocessors and hosting regions;
- notify affected customers of confirmed security incidents involving their data;
- continuously improve our security practices as SyncHive grows.
We are implementing an ISO 27001-aligned Information Security Management System. Certification is in progress. Until certification is complete, SyncHive does not claim to be ISO 27001 certified.
2. Data hosting and regions
SyncHive uses Amazon Web Services to host the SyncHive platform.
Customers may choose the hosting region for each Hive when the Hive is created, where region selection is available.
Current Hive hosting regions are:
| Region | Provider |
|---|---|
| US West (Oregon), United States | Amazon Web Services |
| Asia Pacific (Sydney), Australia | Amazon Web Services |
Customer Hive Data is hosted in the selected Hive region.
Backups and logs relating to Hive Data remain in the selected Hive region.
3. Data ownership and use
Customers retain ownership of their Customer Data.
SyncHive processes Customer Data only as needed to provide, operate, secure, support, maintain, and improve the reliability of the service, comply with law, and enforce our Terms.
SyncHive does not sell Customer Data.
SyncHive does not use Customer Data to train artificial intelligence or machine learning models.
SyncHive may collect and use logs, telemetry, usage data, token consumption data, performance data, and diagnostic information to:
- operate the service;
- calculate usage and billing;
- monitor reliability and performance;
- troubleshoot issues;
- detect and prevent misuse;
- investigate security incidents;
- improve service stability and security.
SyncHive may use aggregated, anonymised, or de-identified information where it does not identify a customer, user, or individual.
4. Encryption
SyncHive encrypts data in transit and at rest.
Data transmitted to and from SyncHive is protected using industry-standard transport encryption.
Stored data and backups are encrypted at rest using cloud provider encryption capabilities.
5. Access control
SyncHive supports role-based access control at both Workspace and Hive level.
Customers are responsible for managing their own users, roles, permissions, and access decisions.
Internally, SyncHive restricts access to production systems and customer data to authorised personnel who require access for legitimate operational, security, support, or maintenance purposes.
6. Authentication and MFA
SyncHive supports optional multi-factor authentication.
Customers are responsible for:
- enabling MFA where appropriate;
- maintaining secure passwords and credentials;
- removing access for users who no longer require it;
- assigning appropriate Workspace and Hive permissions;
- protecting API keys, access tokens, credentials, and integration secrets.
We strongly recommend enabling MFA for administrative users.
7. Backups and recovery
SyncHive maintains backups for disaster recovery and business continuity.
Hive backups remain in the selected Hive region.
Deleted Customer Data may remain in encrypted backups for up to 30 days after deletion from active systems, after which it expires through normal backup rotation.
8. Logging and monitoring
SyncHive collects logs, telemetry, and usage data to operate, secure, monitor, troubleshoot, and improve service reliability.
9. Incident response
SyncHive maintains processes for identifying, assessing, escalating, responding to, and reviewing security incidents.
10. Subprocessors
SyncHive uses selected third-party service providers to host, secure, support, maintain, and operate the service.
11. Privacy and data protection
SyncHive is operated by a New Zealand company and is designed to support obligations under the New Zealand Privacy Act 2020, Australian privacy requirements, and GDPR-style processor obligations where applicable.
12. Restricted data and high-risk use
Customers must not use SyncHive to process sensitive, regulated, payment, health, biometric, children's, government identifier, credential, or other restricted data unless SyncHive has expressly approved that use in writing.
13. Secure development and change management
SyncHive follows controlled development and deployment practices.
14. Supplier and vendor management
SyncHive uses selected suppliers to provide and operate the service.
15. Customer security responsibilities
Security is a shared responsibility.
16. Vulnerability reporting
If you believe you have found a security vulnerability in SyncHive, please contact us promptly at: privacy@synchive.com
17. Contact
For privacy or security questions, contact:
Meaningful Technology Ltd trading as SyncHive
Level 2, 110 Symonds Street
Grafton, Auckland 1010
New Zealand
Email: privacy@synchive.com
18. Changes to this page
We may update this page from time to time to reflect changes to our security practices, suppliers, infrastructure, legal documents, or product functionality.