PowerSycPro Version 3.x Trust Centre - IaaS


PowerSyncPro v3.x is a customer-deployed solution for directory synchronisation and workstation migration.

All PowerSyncPro v3.x components are installed and operated within customer-managed or partner-managed infrastructure.

PowerSyncPro does not host, operate, or manage infrastructure for the v3.x IaaS offering and does not maintain persistent access to customer environments.

PowerSyncPro v3.x is deployed entirely within customer-controlled or partner-controlled infrastructure.

The v3.x deployment model includes:

• Customer-managed infrastructure
• No vendor-hosted control plane
• No persistent vendor access
• Support provided only through customer-initiated engagement, such as screen sharing, logs, or customer-approved diagnostic information

Customers retain control over infrastructure, data location, network configuration, access policies, backup, monitoring, and operational procedures.

PowerSyncPro is responsible for developing and maintaining the PowerSyncPro software. Customers are responsible for deploying, configuring, operating, securing, and monitoring the environment in which the software runs.

PowerSyncPro v3.x consists of the following components:

• Central Server — Windows, .NET 8, Kestrel
Optional reverse proxy
• Optional agents, including:
• Workstation Migration Agent
• Remote Sync Agent
• Remote Password Agent
• Remote Proxy Agent

All components are built using .NET and follow consistent secure communication patterns.

 

 

PowerSyncPro v3.x components are designed so that agents initiate outbound connections to the Central Server.

Current v3.x communication patterns include:

• Communications encrypted using TLS
• Initial trust established using a pre-shared key during installation
• Remote agents explicitly approved before use
• Per-agent, one-time-only pre-shared keys for remote agents
• Mutual certificate authentication for subsequent communications
• Payload-level encryption using AES-256 with a new AES key per communication, protected using RSA
• Typical ports:
• TCP 443 for Workstation Migration Agent communications
• TCP 5001 for Directory, Password, and Proxy Agent communications

Agents are typically deployed on trusted customer endpoints or within known customer-owned IP ranges.

The agent endpoint has been penetration tested by a third-party security vendor.

No operational migration or synchronisation traffic is transmitted from customer-controlled PowerSyncPro v3.x components to PowerSyncPro-controlled production systems as part of normal product operation.

Customers are responsible for securing network paths, firewalls, reverse proxies, certificates, and other infrastructure controls within their environment.

PowerSyncPro v3.x supports integration with the following directory and identity platforms:

• Active Directory
• Microsoft Entra ID
• Google Directory

Connectivity options are customer-configurable and include TLS-secured protocols where supported.

Where non-encrypted directory protocols are required by the customer’s environment or configuration, customers are responsible for ensuring appropriate network-level protections, such as trusted networks, VPNs, private connectivity, segmentation, or other compensating controls.

PowerSyncPro v3.x is designed to minimise password and credential exposure.

Password and credential handling controls include:

• PowerSyncPro v3.x is not designed to persist password hashes
• Plaintext passwords are not persisted unencrypted
• Password material is processed only where required to perform authorised password operations
• Passwords are encrypted using endpoint-specific certificates where applicable
• Encrypted passwords are transferred securely
• Password material is not retained after processing except where required for the authorised operation and protected by customer-controlled infrastructure

Customers remain responsible for controlling credential scope, administrative permissions, service accounts, and access to systems used by PowerSyncPro v3.x.

PowerSyncPro v3.x stores product data in customer-managed SQL Server environments.

Data protection controls include:

• SQL connections protected using certificates where configured
• Sensitive data encrypted prior to storage
• Encryption keys protected using DPAPI or DPAPI-NG
• Group Managed Service Accounts recommended where appropriate
• PowerSyncPro does not manage or escrow customer encryption keys for v3.x deployments

Customers are responsible for SQL Server security, backup, retention, monitoring, patching, administrator access, and key protection within their environment.

PowerSyncPro v3.x accesses and stores data required to identify, match, report on, synchronise, and migrate objects according to customer configuration.

A baseline set of object identifiers and directory attributes is required for core product functionality. These may include identifiers, names, directory paths, account names, email-related attributes, account state, object type, group type, and Exchange-related attributes required for matching, reporting, and synchronisation.

Typical mandatory attributes include:

• objectGUID / objectId
• objectSID
• Name / DisplayName
• cn
• distinguishedName
• UserPrincipalName
• SamAccountName
• UserAccountControl / AccountEnabled
• Mail / Email Address
• LegacyExchangeDN
• msExchRecipientDisplayType
• msExchRecipientTypeDetails
• msExchHideFromAddressLists
• msExchPoliciesIncluded
• msExchPoliciesExcluded
• ShowInAddressBook
• ReportToOriginator
• TargetAddress
• MailNickName / Alias
• GroupType / GroupTypes

Beyond mandatory attributes required for product functionality, only customer-configured directory attributes are accessed and stored.

What-if reporting enables customers to preview proposed changes before execution.

PowerSyncPro v3.x does not transmit product telemetry or operational logs to PowerSyncPro-controlled infrastructure as part of normal product operation.

Logs remain within customer-controlled infrastructure unless the customer chooses to provide logs to PowerSyncPro for support, troubleshooting, or investigation.

Log retention, log access, monitoring, alerting, and log export are controlled by the customer.

Customers should review logs before providing them to PowerSyncPro and should avoid sending credentials, secrets, or unrelated personal data.

PowerSyncPro does not maintain persistent access to customer v3.x environments.

Support is provided through customer-initiated channels, such as support tickets, customer-approved screen sharing, customer-provided logs, or customer-approved diagnostic information.

Customers control whether PowerSyncPro personnel are granted access to customer systems and remain responsible for monitoring, approving, and revoking such access.

For PowerSyncPro v3.x deployments, backup, availability, disaster recovery, and resilience are customer responsibilities.

Customers are responsible for protecting the infrastructure, databases, configuration, certificates, encryption keys, and systems required to operate the v3.x deployment.

PowerSyncPro recommends that customers apply backup, monitoring, patching, and disaster recovery controls appropriate to the criticality of their migration or synchronisation environment.

PowerSyncPro v3.x is developed and maintained under PowerSyncPro’s ISO/IEC 27001-certified Information Security Management System and ISO/IEC 9001-certified Quality Management System.

The product is designed and maintained in alignment with industry security best practices, including secure development, controlled release management, vulnerability management, and least-privilege principles.

Because v3.x is deployed into customer-controlled infrastructure, many operational controls depend on the customer’s environment, configuration, policies, and administrative practices.

For PowerSyncPro v3.x, customers are responsible for:

• Provisioning and securing infrastructure
• Managing operating systems, SQL Server, certificates, service accounts, and network controls
• Applying appropriate backup, recovery, monitoring, and patching processes
• Managing administrative access
• Defining synchronisation and migration scope
• Protecting credentials and external system access
• Reviewing configuration and what-if reports before applying changes
• Ensuring compliance with their own legal, regulatory, and organisational obligations