Skip to main content

Security

Trust built from specifics, not badges.

Your Workspace holds other people's personal details and your own financial records. These are the concrete guarantees behind them.

For the formal statement, read the Security and Incident Response Statement.

Tenancy

The Workspace is the boundary

Scoped on the server

Every Client, Plan, package and revenue record belongs to one Workspace. Access is resolved and enforced in the backend, so a request cannot reach another Workspace's data by asking differently.

Ownership is never sent by the browser

Workspace, currency and the acting Professional are derived from your authenticated session, not from values the interface could supply.

Records cannot be linked across Workspaces

The database itself enforces that a Client, a Client Subscription and a revenue record belong to the same Workspace.

Roles are separated

Workspace operations require a Professional account. Platform administration is a separate role with its own routes and its own audit trail.

Integrity

History you can rely on

Financial records are added, never rewritten

There is no path that edits or deletes a payment. A refund or adjustment is a new record, and the original stays readable.

Session history works the same way

Using and restoring a session are both recorded, with who did it and when.

Repeating an action does not duplicate it

Sessions and payments carry a request identifier, so a retry, a double click or a lost connection cannot record the same thing twice.

Refunds cannot exceed the payment

A refund is checked against what that payment actually collected, including refunds already recorded against it.

Money is stored as whole units

Amounts are held as exact integer minor units, so rounding never quietly changes a total.

Archiving replaces deletion

Plan changes and cleanups archive records instead of destroying them, so past work stays available.

Providers

Who handles what

Stripe handles your subscription payments

Card details are entered with Stripe and processed by Stripe. NotiSynk does not see or store your card number or security code.

Meta delivers WhatsApp messages

WhatsApp reminders go through the official WhatsApp Business Platform, using approved templates and requiring the Client's consent.

Delivery callbacks are verified

Status updates from the messaging provider are signature-checked and de-duplicated before they are trusted.

Operational logs stay clean

Full phone numbers, message bodies, tokens and raw provider payloads are kept out of operational logs.

Your Clients

Your Clients are not NotiSynk's customers. You decide who is contacted, on which channel, and how often, and WhatsApp requires an explicit consent record that a phone-number change revokes.

What we do not claim

NotiSynk does not hold a security certification, and this page does not imply one. What is described here is how the product is built and which providers it relies on. Read the Security and Incident Response Statement for the formal position, and the Subprocessor notice for the full provider list.

Start today

Set up your Workspace in a few minutes.

Add your first Clients, create the Plans you already sell, and let NotiSynk handle the follow-up.

Free covers up to 10 active Clients and 10 active Client Subscriptions.