We hold as little of your data as the job allows
Here is exactly what that means — what passes through us, what never does, where the work runs, and how long anything survives once a migration is finished.
The recordings don’t need to live with us
On most migrations the destination collects the media directly from your source system, and the files never enter our infrastructure at all. Where that is not possible, they pass through storage you own, under your keys.
What our systems keep is the bookkeeping: which record went where, what state it reached, and the checksums that prove it arrived intact. The ledger, not the conversations.
The destination pulls each recording straight from your source system over a signed URL. Files never pass through Syncavo, and it is the faster of the two routes.
Three ways your media can move
Which one applies is decided during scoping, from what your source system can actually do — and it is written into your engagement rather than left as an implementation detail.
| Direct transfer | Your storage | Through us | |
|---|---|---|---|
| Media at rest with us | Never | Never | Briefly, encrypted |
| Media passing through us | Never | Never | Yes |
| Who holds the encryption keys | Not applicable | You do | We do, in region |
| When it is deleted | Not applicable | Your retention policy | On verification of the record |
| When this applies | Source produces durable links | Links expire too quickly | Files need converting first |
We name the third column rather than hiding it. Some source systems produce links that expire within hours, or files in formats the destination will not accept, and in those cases the media genuinely does pass through our workers. It runs in your region, encrypted, and is deleted the moment the record is verified — but it is a different posture from the other two, and it is described as one.
Encryption
Everything in transit moves over TLS. Everything we keep at rest is encrypted, and the personal data inside our own records — names, email addresses, the mapping tables — is encrypted at the field level as well.
Where the work runs
Migrations run in the region your data already lives in, and the job will not dispatch across a regional boundary. For most customers this satisfies residency requirements without any bespoke arrangement.
Credentials
We ask for scoped, time-limited credentials issued for the engagement, never a shared administrator login. They are stored encrypted, used only by the workers that need them, and revoked at the end of the migration — by you, not on trust.
Access
Only the engineers running your migration can reach its systems, through individually issued accounts with multi-factor authentication. Access is logged, and it ends when the engagement does.
What we keep, and for how long
Job records, mapping tables and reconciliation reports are kept for 90 days after a migration is signed off, so we can support questions that surface later. After that they are deleted. You can ask for deletion sooner, and we will confirm when it is done.
Audit trail
Every record carries its own history — when it was extracted, its checksum, when it was verified at the destination. That trail is yours at the end of the engagement, and it is what makes the migration defensible if a regulator or auditor asks.
What we haven’t got yet
We hold no security certifications today. We are not going to put a badge on this page that we have not earned, or imply a timeline we cannot commit to.
What we can do is answer your security questionnaire directly, walk your team through exactly how an engagement handles data, and agree controls in writing before any credentials change hands. If a certification is a hard requirement for your procurement process, tell us early — it is better to know than to spend three weeks discovering it.
Documents
What your legal and security teams will ask for. Anything not published here, we will send on request.
- Data processing agreementOur standard DPA, covering processing terms, subprocessors and international transfers.
- SubprocessorsEvery third party involved in delivering a migration, what they do, and where they run.
- Privacy policyWhat we collect from visitors and customers, and why.
- Security questionnaire responsesOn requestWe answer yours directly rather than publishing a generic one. Ask during scoping and we will turn it round with the proposal.
Bring us your security review.
We would rather answer the hard questions before an engagement than during one. Tell us what you are moving and what your team needs to see.