The stance
This page is intentionally honest about what is and is not certified. Graphor is operated by Synapse Inovação e Tecnologia LTDA., a company at an early-stage. It does not yet hold its own SOC 2 Type II or ISO 27001 certification. Stating that openly is the first compensating control. What this page commits to:- No aspirational certification dates. Where a certification is under evaluation, the page says so without binding to a delivery date. When a date is committed, this page is updated and the change history at the bottom records it.
- Every control claim in the rest of the Trust Center is verifiable. Each row in the compensating-controls inventory below links to the Trust Center page that documents the control in implementation detail.
- Inherited certifications are listed verbatim with links. Where Graphor relies on a subprocessor’s certified posture, the certification is named with its issuing standard and the customer can read the same report under NDA.
1. Synapse’s own certification status
The “evaluating” status on SOC 2 Type II and ISO 27001 reflects an active assessment of when it makes sense to enter the audit cycle. Enterprise contracts that require either certification can accelerate the timeline — see §6.
2. Inherited certifications
Graphor’s operational stack runs on subprocessors that carry the certifications listed below. Inheritance is not a substitute for Graphor holding its own certification, but it is the standard way that a SOC 2-pending company demonstrates that the upstream chain meets enterprise security expectations.
Each subprocessor’s audit reports can be requested through Synapse via privacy@graphorlm.com; the report itself is delivered by the subprocessor under their own NDA terms.
3. Compensating controls inventory
In the absence of Synapse’s own SOC 2 or ISO 27001 certification, the following operational controls — already in place and documented elsewhere on the Trust Center — cover the gap that the certification would otherwise demonstrate.
Enterprise customers performing a Graphor-specific security questionnaire can use this table as a cross-reference: for each line item on the questionnaire, identify the relevant control area and follow the link to the implementation detail.
4. Regime-based posture (LGPD, GDPR)
LGPD and GDPR are regulatory regimes, not certification schemes — there is no formal “LGPD-certified” stamp. Graphor’s posture against each is documented as compliance by design, with the relevant articles cited next to the control that satisfies them:5. Business continuity and key-person risk
Synapse is operated by SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA., currently founder-led. A founder-led operation carries an explicit key-person risk that customers should evaluate at signature. This section discloses what mitigates that risk today and what does not.5.1 What is in place
- Provider redundancy for inference. AWS Bedrock and Cerebras are both active subprocessors; if one provider’s availability degrades, traffic is routed to the other within the per-tier provider chain documented in Model Use and Training §1.2.
- Data durability. Cloud-provider automated backups + point-in-time recovery within a 7-day window for the primary database; object-storage redundancy at the cloud-provider tier; managed-graph-store provider redundancy per Subprocessors §2. See Data Retention §5.
- External incident-alerting service. Inbound mail to the privacy mailbox triggers an external alert that routes to the on-call engineer, providing notification continuity independent of any single device.
- Backup-access procedure (operationalizing). Synapse is operationalizing a credential-recovery arrangement for the event of founder incapacitation. The current interim measure is a sealed-credential procedure with a named alternate operations contact (a Brazilian licensed attorney) who can revoke credentials, freeze the production environment, and trigger customer notification under the Incident Response SLA. A formal third-party escrow arrangement (cartório or commercial escrow provider) is on the roadmap; the current arrangement and the named alternate contact are disclosed to enterprise customers under NDA.
- Stateless customer integration. Customers integrate via the public REST + streaming API; there is no Synapse-deployed customer-side agent that would fail if Synapse-side operations paused.
5.2 What is NOT in place (honest disclosure)
- No 24/7 in-house SecOps rotation. Severity-1 and Severity-2 alerts route to the founder + external alerting service today. Synapse is investing in a 24/7 escalation path as the team scales; the current model is disclosed rather than overstated.
- No active-active multi-region deployment. Per Data Residency §5, the single-region posture is intentional; the Brazil and EU region roadmap items in Data Residency §6 provide a customer-driven path to regional alternatives, not active-active redundancy.
- No published RTO/RPO commitments today, and no end-to-end restore drill has been run. The point-in-time recovery within the 7-day backup window targets sub-hour RPO under normal operation (per the cloud-provider PITR granularity, typically seconds-to-minutes); an effective RTO for a full-region rebuild is on the order of hours and depends on the cloud-provider control plane. Quantified RTO/RPO targets will be published once an annual restore-drill cadence is established.
- No formal vendor-termination wind-down playbook today. A customer-data export path is available on request via privacy@graphorlm.com; a published wind-down playbook is on the roadmap.
- No published company-dissolution playbook today. In the event of voluntary or involuntary dissolution of Synapse Inovação e Tecnologia LTDA., Customer Content would be subject to standard Brazilian corporate-dissolution procedures under the Código Civil arts. 1.033–1.038 (sociedade limitada) and the LGPD obligations that survive dissolution. A formal commitment to (a) provide a 30-day customer-data export window on dissolution notification, (b) certify destruction of remaining Customer Content within 60 days of dissolution, and (c) name a Brazilian licensed attorney as the post-dissolution data-protection contact is available as a contractual rider on enterprise engagements on request. A published dissolution playbook is on the roadmap.
5.3 What customers should do
Customers with stringent business-continuity requirements (regulated financial-sector workloads, healthcare BAA-equivalent, government engagements) should:- Discuss BCP scope at contract signature, including target RTO/RPO and a vendor-termination wind-down clause specific to the engagement;
- Maintain an independent export of Customer Content at a cadence appropriate to the workload (Graphor provides export on request, and a self-service export API is on the roadmap);
- Subscribe to subprocessors@graphorlm.com to receive material-change notifications that may affect continuity posture.
6. How to request audit reports and discuss certification needs
For enterprise customers:- Subprocessor audit reports (Google SOC 2, AWS SOC 2, OpenAI SOC 2 Type 2, etc.): request via privacy@graphorlm.com. Reports are delivered by the subprocessor under their own NDA terms.
- A formal Synapse certification commitment (specific SOC 2 timeline, ISO 27001 scope agreement, HIPAA BAA): request via privacy@graphorlm.com. An enterprise contract with a binding certification clause is the path to bringing a specific audit cycle forward.
- A DPIA / Legitimate Interest Assessment specific to your processing activity: Synapse can provide a Graphor-side template that you complete with your processing details, on request via privacy@graphorlm.com.
- A custom security questionnaire: Synapse will complete reasonable enterprise security questionnaires within 10 business days of receipt, citing the Trust Center pages above for the answers wherever they apply.
Executive intent statement
Synapse Inovação e Tecnologia LTDA. — the operator of Graphor — is committed to building the controls, the operational discipline, and the audit posture that regulated enterprise customers require. We are honest about what is certified today and what is not. We do not publish aspirational dates that we may miss. We do publish, in detail, the controls that are in place in lieu of those certifications, and we welcome customer audits of those controls under reasonable scoping. — Lucas Neves, Founder & CEO, Synapse Inovação e Tecnologia LTDA.
7. Change history
When a certification status changes (audit started, audit completed, scope expanded), this table is updated and subscribers to subprocessors@graphorlm.com receive an email.
Contact
- Compliance, audit, and certification inquiries: privacy@graphorlm.com
- Subscription to compliance-status change notifications: subprocessors@graphorlm.com
- Customer support: support@graphorlm.com

