SECURITY & COMPLIANCE

    Security & Compliance at Syntra ETL

    Migration means trusting a partner with your most sensitive data — financials, payroll, PII and PHI. Syntra ETL is built for that responsibility: ISO 27001 certified, SOX and GDPR compliant, with encryption, least-privilege access and full audit logging across every engagement.

    ISO 27001
    Certified
    SOX
    Compliant
    GDPR
    Compliant
    Encrypted
    In transit & at rest

    How we protect your data during a migration

    Security isn't a checkbox at the end — it's designed into how data is extracted, staged, transformed, loaded and deleted across the migration lifecycle.

    Your data is encrypted in transit and at rest, access is role-based and least-privilege, and every access is logged for audit. We minimize the data we handle, isolate each engagement, and securely delete staged data when the migration completes.

    We operate under an information-security management system aligned to ISO 27001, support SOX control requirements for financially-relevant data, and handle personal data in line with GDPR — including Data Processing Agreements and, where applicable, appropriate handling for health data. Our security documentation, DPA and (where in place) certificates are available to prospects and customers on request.

    Certifications & frameworks

    The standards we operate to.

    🛡️

    ISO 27001

    An information-security management system aligned to ISO 27001 governs how we protect data, manage risk and respond to incidents.

    📊

    SOX

    We support Sarbanes-Oxley control requirements for financially-relevant data, with reconciliation evidence and audit trails.

    🇪🇺

    GDPR

    Personal data is processed lawfully and minimally, with Data Processing Agreements and data-subject-rights support.

    🔐

    Encryption

    Data encrypted in transit (TLS) and at rest, with key management controls.

    👤

    Access control

    Role-based, least-privilege access with full audit logging.

    🩺

    Health data

    HIPAA-aligned handling where protected health information is in scope.

    Security across the migration lifecycle

    Controls at every stage.

    1

    Data minimization

    We handle only the data needed for your migration, scoped up front.

    2

    Secure extraction

    Encrypted connections to source systems; credentials handled under least privilege.

    3

    Isolated staging

    Each engagement is isolated; staged data is encrypted and access-controlled.

    4

    Controlled load

    Loads to your Oracle Fusion environment under governed, logged access.

    5

    Audit evidence

    Reconciliation and access logs provide an auditable trail for SOX and internal audit.

    6

    Secure deletion

    Staged data is securely deleted when the migration completes, per agreement.

    Data handling practices

    How your data is governed.

    🔒

    Encryption everywhere

    TLS in transit; encryption at rest with managed keys.

    📝

    Audit logging

    Every access and action is logged and reviewable.

    🌍

    Data residency

    Residency options to meet regional and regulatory needs (on request).

    🤝

    Sub-processor governance

    Sub-processors managed under contract and disclosed in the DPA.

    🗑️

    Secure deletion

    Staged data destroyed on completion under documented policy.

    📄

    DPA & docs

    Data Processing Agreement and security documentation available on request.

    Frequently asked questions

    Is Syntra ETL ISO 27001 certified?+

    Yes — Syntra ETL operates an information-security management system aligned to ISO 27001. Our current certificate and supporting documentation are available to prospects and customers on request.

    Are you SOX and GDPR compliant?+

    Yes. We support Sarbanes-Oxley control requirements for financially-relevant data (with reconciliation evidence and audit trails), and we process personal data in line with GDPR, including offering a Data Processing Agreement (DPA) and supporting data-subject rights.

    How is our data encrypted?+

    Data is encrypted in transit using TLS and at rest using strong encryption with managed keys. Access is role-based, least-privilege and fully logged.

    Do you sign a DPA (and BAA for healthcare)?+

    Yes — we provide a Data Processing Agreement for personal data, and where protected health information is in scope we support HIPAA-aligned handling and the appropriate agreements. Contact us to put these in place.

    What happens to our data after the migration?+

    Staged data is securely deleted on completion of the engagement under a documented policy. Any long-term archive you commission is retained under the retention rules you specify, with access controls and audit logging.

    Can we review your security documentation before engaging?+

    Yes — request our security overview, DPA, sub-processor list and (where applicable) certificates, and we'll share them under NDA as needed.

    Request Our Security Documentation

    Need our DPA, security overview or compliance certificates for vendor review? Tell us what your security team needs and we'll provide it.