Skip to main content

What this is

The Graphor Trust Center is the canonical, public record of how Graphor handles customer data. It is intended for security, privacy, procurement, and compliance teams evaluating Graphor for use under LGPD, GDPR, and equivalent regimes. Graphor is operated by SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA., a company organized under the laws of the Federative Republic of Brazil. Every claim on this site is verifiable against the running production system or against a cited third-party document. This page summarizes the posture across nine dimensions in one place. Each row links to the detail page that owns the topic — when an SI questionnaire asks about a specific area, follow the link and you will find the structured, source-of-truth answer.

1. The summary

2. Data flow at a glance

The customer interacts with Graphor through one of four authenticated surfaces (UI, REST API, streaming, MCP transports). Each request is authenticated and scoped to a single Project before any customer-content store is touched. The complete ingestion and query sequences (with sub-component detail) are in Architecture §2 and §3.

3. Encryption posture

Encryption posture for the AI-provider subprocessors is governed by each provider’s own commitments — see Model Use and Training §4 for the verbatim citations.

4. The Trust Center pages

5. How to read this site

  • For an enterprise SI evaluation: start with this page for the one-pager, then read Subprocessors, Model Use, and Data Retention — they cover the questions on most LGPD/GDPR/EOAB checklists. Use the DPA template to start the contractual conversation.
  • For procurement: the Compliance page lists what is certified and what is not, with inherited certifications and compensating controls. Synapse can provide subprocessor audit reports under NDA on request.
  • For privacy / DPO review: Privacy Policy (LGPD art. 18 and GDPR art. 15–22 rights), Data Retention (the DSR API), Data Residency (LGPD art. 33 international-transfer regime).
  • For developer integration questions (API auth, rate limits, SDK, MCP): the Documentation, SDK, and API Reference tabs of this site.

6. Subscribing to changes

When any Trust Center or Legal page changes materially, subscribers to subprocessors@graphorlm.com receive a single notification email per change with a summary and the link to the new revision. Material additions to the subprocessor inventory are published at least 30 days before they take effect in production, except when the addition is required to remediate an active security incident.

7. Change history

Contact