Security

Built for clubs handling real money and real member data.

SyncReserve runs reservations, payments, memberships, and member messaging. Security is part of how the platform is built and operated.

Compliance posture

Frameworks behind the platform.

SyncReserve runs on enterprise cloud infrastructure and payment providers that maintain their own attestations: Stripe (PCI DSS Level 1) for payments, and our cloud and database providers' SOC 2 Type II and ISO 27001 programs.

SyncReserve itself does not hold these certifications.

How we operate

Controls clubs can actually defend.

Infrastructure & hosting

  • Hosted on enterprise cloud infrastructure whose providers maintain SOC 2 Type II, ISO 27001, and PCI DSS attestations.
  • Global edge network, automatic TLS, HTTPS-only delivery, and DDoS mitigation.
  • Web Application Firewall managed rulesets covering OWASP Top 10.

Data protection

  • Customer data, databases, file storage, and search indexes are encrypted at rest.
  • Data is encrypted in transit for external and internal traffic.
  • Secrets live in encrypted environment configuration, never in source.

Payments

  • Card data is processed and stored by Stripe, a PCI DSS Level 1 Service Provider.
  • SyncReserve never sees raw card numbers, CVCs, or full bank credentials.
  • Refunds, disputes, and payout reconciliation are logged with audit trail.

Access control

  • Owner, Manager, Staff, and Coach roles are scoped to a single tenant.
  • Tenant ID is enforced server-side on every read and write.
  • Sensitive admin actions are logged with actor, timestamp, and target.
Responsible disclosure

Found a vulnerability? Tell us.

Reach out through the contact page and flag your message as a security report. We respond within two business days for in-scope reports and credit researchers who follow coordinated disclosure.

Walk through security with the team building it.

Architecture, sub-processors, data processing terms, and incident process are all fair game before you commit.