The PowerSyncPro Trust Centre
Trust & security at PowerSyncPro
PowerSyncPro is committed to protecting customer data through strong security controls, transparent practices, and a mature information security programme aligned with international standards.
This Trust Centre provides baseline security, privacy, and compliance information for the following PowerSyncPro products. Product-specific pages provide additional details relevant to each product:
• PowerSyncPro v3.x IaaS — Directory Synchronisation & Workstation Migration
This Trust Centre is intended to provide transparency into PowerSyncPro’s security and compliance practices. It does not replace contractual agreements, data processing agreements, customer security assessments, or other legally binding documents
PowerSyncPro operates an ISO/IEC 27001-certified Information Security Management System covering the development, operation, and support of its products.
The security programme is designed around:
• Least-privilege access
• Defence in depth
• Data minimisation
• Secure-by-default architecture
• Controlled change management
• Continuous improvement
PowerSyncPro’s security controls are reviewed and improved as part of the ongoing operation of the Information Security Management System.
As part of its ISO/IEC 27001-certified Information Security Management System, PowerSyncPro maintains a formal risk management process.
Security risks are identified, assessed, treated, and reviewed on an ongoing basis. Risk treatment decisions are reviewed by management and are informed by the potential impact to customers, service availability, confidentiality, integrity, compliance obligations, and business operations.
PowerSyncPro maintains the following compliance and assurance activities:
• ISO/IEC 27001 certified
• ISO/IEC 9001 certified
• Selected controls aligned to the SOC 2 Trust Services Criteria for Security and Availability as part of the assurance roadmap
• Evaluation of additional assurance frameworks, including SOC 2 reporting and Microsoft attestations, as part of the compliance roadmap
PowerSyncPro may provide additional assurance information to customers subject to appropriate confidentiality and contractual arrangements.
PowerSyncPro follows a controlled secure development lifecycle covering design, development, testing, review, release, and operational feedback.
PowerSyncPro’s secure development practices include:
• Development tracked and managed in Azure DevOps
• Features, bugs, security issues, and technical work tracked as work items
• Code changes made through pull requests and subject to review and approval before merge
• Additional review requirements applied according to repository, branch, product, and change risk
• Production CI/CD pipelines run on controlled Azure build infrastructure
• Microsoft Defender and related scanning controls integrated into relevant CI/CD and container image workflows
• Container images scanned for known vulnerabilities
• Identified vulnerabilities prioritised and remediated through the development backlog
• Security and operational lessons incorporated into future development activity
PowerSyncPro uses human review, automated checks, and controlled release processes to reduce the risk of unauthorised, unreviewed, or unsafe changes.
PowerSyncPro follows controlled change management practices for production-impacting changes.
Changes are assessed, reviewed, tested, approved, and deployed through managed processes appropriate to the risk and scope of the change. Production changes are performed by authorised personnel and are subject to logging, review, and rollback or corrective action where appropriate.
Emergency changes may be expedited where required to protect security, availability, or customer impact, but remain subject to review and follow-up.
PowerSyncPro performs security testing appropriate to its risk profile, including automated vulnerability scanning, dependency analysis, container image scanning, and secure configuration reviews.
Additional testing approaches, including penetration testing, external assessment, and broader assurance activities, are evaluated as part of the ongoing security programme and product maturity roadmap.
PowerSyncPro maintains formal vulnerability and security incident management processes covering:
• Vulnerability identification, triage, remediation, and verification
• Dependency, container image, operating system, and platform patching
• Security monitoring, incident detection, response, escalation, and post-incident review
Vulnerabilities and security incidents are assessed using a risk-based severity model that considers factors such as exploitability, business impact, affected systems, data sensitivity, customer exposure, service availability, and the availability of compensating controls.
For vulnerabilities, remediation is prioritised according to assessed severity and may include patching, dependency updates, configuration changes, additional monitoring, customer-specific mitigations, or other risk-reducing actions.
For security incidents, PowerSyncPro follows a formal process for triage, containment, investigation, recovery, customer notification where applicable, and post-incident review.
Critical and high-severity issues are prioritised for urgent investigation, containment, and remediation according to the assessed risk.
Where a security incident affects customer data or service availability, PowerSyncPro notifies affected customers in accordance with applicable contractual, legal, and regulatory requirements.
Following significant incidents, PowerSyncPro performs a post-incident review to identify root causes, lessons learned, and corrective or preventive actions.
PowerSyncPro applies the following data protection principles across its offerings:
• Encryption in transit using TLS
• Encryption at rest using industry-standard mechanisms
• Logical isolation of customer data
• Customer-defined scope of data processing
• Data minimisation
• Least-privilege access to customer data
• No sale of customer data
• No use of customer data for advertising or unrelated profiling
Customer data is used only to provide, secure, support, operate, bill for, and improve the contracted services, and as otherwise required by law or agreement.
Data is classified based on sensitivity, and security controls are applied proportionally. These controls may include access restrictions, encryption, retention limits, logging, monitoring, and operational review.
Customers retain ownership of their data and control the scope of data they authorise PowerSyncPro to process.
For customer migration data processed under a customer agreement, PowerSyncPro generally acts as a data processor. PowerSyncPro may act as a controller for limited business operations data, such as sales, billing, website, security, account administration, support, and customer relationship records.
Customer data is processed only for authorised purposes, including service delivery, security, support, operations, billing, compliance, and other purposes described in applicable agreements or privacy documentation.
Access to PowerSyncPro systems, production environments, and customer data is restricted to authorised personnel based on role and business need.
Access is granted through approved processes, follows least-privilege principles, and is reviewed periodically. Access is removed or updated when no longer required, including when personnel change role or leave the organisation.
Personnel and contractors with access to PowerSyncPro systems are subject to confidentiality obligations, security policies, and oversight appropriate to their role.
PowerSyncPro uses the subprocessors listed below to provide, operate, secure, support, improve, and bill for the PowerSyncPro services.
Each subprocessor is subject to contractual obligations, confidentiality requirements, access controls, and security oversight appropriate to the processing performed.
Where PowerSyncPro acts as a processor on behalf of a customer, subprocessors may process customer personal data only as necessary to provide the relevant service.
The subprocessor table below was last updated: 17th June 2026.
|
Subprocessor |
Services used |
Purpose |
Data categories |
|
Microsoft |
Azure, including Azure Container Apps, Azure SQL, Azure Key Vault, Azure Container Registry, Azure Monitor, Application Insights, Log Analytics, Azure Data Explorer, Azure Front Door with WAF, Azure Backup, Azure Communication Services and Email Communication Services |
Cloud hosting, infrastructure, storage, databases, secrets management, logging, monitoring, diagnostics, analytics, backup, network protection, security, notifications, and service operation |
Customer tenant data, service configuration data, directory attributes, user identifiers, group membership, device identifiers, tenant IDs, logs, diagnostic data, telemetry, IP addresses, authentication metadata, and other technical metadata |
|
Microsoft |
Entra ID |
Authentication, identity, access control, tenant integration, and directory-related service functionality |
User identifiers, directory attributes, group membership, tenant IDs, authentication data, access logs, and identity metadata |
|
Microsoft |
Azure DevOps |
Source code management, software development lifecycle, issue tracking, release management, CI/CD, and secure service operations |
Limited technical data, issue information, development records, logs, diagnostic data, and support/development workflow information |
|
Xopero |
GitProtect |
Backup for Azure DevOps |
Same as Azure DevOps above |
|
Microsoft |
Microsoft 365, including Exchange, Teams, Bookings, Calendar, SharePoint, and OneDrive |
Business communications, customer meetings, scheduling, administration, document handling, file sharing, collaboration, and operational support |
Customer contact details, business communications, meeting metadata, support-related files, account information, contracts, operational documentation, and files provided by customers |
|
HubSpot |
Website, tracking, forms, surveys, CRM, sales process, knowledge base, support desk, and partner portal |
Website management, analytics, lead capture, surveys, sales, account management, partner management, customer support, ticketing, help documentation, and customer communications |
Website visitor data, business contact details, company details, account information, form submissions, survey responses, support tickets, partner information, communications history, troubleshooting information, attachments, and diagnostic data provided by customers |
|
ProBackup |
ProBackup |
Backup of HubSpot data |
Same as HubSpot above |
|
|
Google Analytics, Google Tag Manager, Google Search Console |
Website analytics, tag management, search performance analysis, and website optimisation |
Website visitor data, device and browser data, IP-derived location data, usage data, referral data, search performance data, and cookie or similar identifiers where applicable |
|
Microsoft |
Bing Webmaster Tools |
Search performance analysis and website optimisation |
Website search performance data, indexing data, referral data, and limited website usage metadata |
|
Ahrefs |
Website analytics and governance tools |
Website governance, SEO analysis, backlink monitoring, search visibility analysis, and website performance review |
Website performance data, search visibility data, backlink data, and limited website analytics data |
|
Stripe |
Payment processing |
Billing, invoicing, payment processing, tax calculation, fraud prevention, and payment-related support |
Billing contact details, payment metadata, transaction information, invoice information, tax-related information, and payment support records |
|
Xero |
Accounting |
Accounting, bookkeeping, reconciliation, financial reporting, and invoice/account records |
Customer billing details, invoice records, payment records, tax information, account details, and financial communications |
|
Control-C |
Control-C |
Backup of Xero |
Same as Xero above |
|
DocuSign |
Electronic signature |
Contract execution, order forms, data processing agreements, commercial agreements, and signature workflows |
Signatory names, business contact details, email addresses, signatures, authentication metadata, contract documents, and signing audit trails |
|
Approved AI service providers |
OpenAI / ChatGPT, Anthropic Claude, xAI Grok, OpenAI Codex, Azure Foundry, and similar AI coding or assistant tools approved by PowerSyncPro |
AI-assisted drafting, coding, troubleshooting, support analysis, documentation, development assistance, and productivity support |
Business communications, limited support context, code, documentation, troubleshooting information, logs, or diagnostic information where submitted by authorised personnel and where permitted under PowerSyncPro’s internal security, privacy, and contractual controls |
PowerSyncPro may use approved AI tools to assist with software development, documentation, support analysis, troubleshooting, and internal productivity.
AI tools are used under PowerSyncPro’s internal security, confidentiality, and acceptable-use controls.
AI tools do not have direct access to PowerSyncPro staging or production environments.
AI-generated code and production-impacting changes remain subject to the same review, testing, approval, and release controls as other changes. AI-generated support, documentation, and operational outputs are reviewed by authorised personnel before external use where appropriate.
PowerSyncPro personnel must not submit customer personal data, credentials, secrets, production access tokens, or other restricted information to AI tools unless the specific tool and processing activity have been approved for that processing and are subject to appropriate contractual, privacy, and security controls.
PowerSyncPro may use employees and individual contractors to perform sales, customer support, software development, security, administration, and service operations activities.
Such individuals act under PowerSyncPro’s authority and access customer personal data only where necessary to provide, maintain, secure, support, or improve the PowerSyncPro services.
Access is subject to confidentiality obligations, role-based access controls, least-privilege permissions, security policies, and oversight.
Individual contractors are not listed separately as subprocessors where they act under PowerSyncPro’s direct authority and access customer personal data only through PowerSyncPro-managed systems.
Where PowerSyncPro engages a third-party organisation to process customer personal data as an independent subprocessor, that organisation will be added to the subprocessor list in accordance with PowerSyncPro’s subprocessor change process.
PowerSyncPro may update its subprocessor list from time to time. The current list of subprocessors is maintained in this Trust Centre.
PowerSyncPro will provide notice of any intended addition or replacement of a subprocessor before the change takes effect. Notice may be provided by updating this Trust Centre, by email to the customer’s designated account, legal, privacy, billing, administrative, or support contact, through a subprocessor notification subscription mechanism, or by another notice method specified in the applicable agreement.
Customers may subscribe to subprocessor change notifications by contacting privacy@powersyncpro.com.
Unless a shorter period is required for security, availability, legal, or urgent operational reasons, PowerSyncPro will aim to provide at least 15 days’ notice before authorising a new or replacement subprocessor to process customer personal data.
Customers may object to a new or replacement subprocessor by notifying PowerSyncPro in writing within the notice period and explaining the reasonable data protection grounds for the objection. PowerSyncPro will work with the customer in good faith to address the objection in accordance with the applicable Data Processing Agreement.
PowerSyncPro maintains business continuity arrangements appropriate to its role, products, and services.
These arrangements are designed to support the continued operation of critical business functions, customer support, service recovery, and incident response. Product-specific availability, backup, and resilience details are described on the relevant product Trust Centre pages where applicable.
Customers are responsible for:
• Managing user identities and access permissions
• Defining migration scope and data selection
• Managing credentials for external source systems
• Ensuring appropriate network protections within their environments
• Reviewing and approving configuration choices relevant to their migration or synchronisation activity
• Complying with their own legal, regulatory, and organisational obligations
PowerSyncPro accepts responsible disclosure reports for suspected security vulnerabilities affecting PowerSyncPro products or services.
Security inquiries and responsible disclosure reports should be sent to:
Support requests should be raised through the customer support portal.
Privacy inquiries may be sent to: