syrup
Book a call
§Legal — Security In effect p. —

Security

What a two-product studio our size actually does about security, written plainly.

Last updated 19 June 2026

The website. Served over HTTPS with TLS 1.2 minimum and HSTS. Security headers on every response: frame denial, content-type protection, restricted referrer and permissions. Static site, no database, no accounts, nothing to breach beyond what you can already see.

Your enquiries. Form and booking data flows through the providers on our subprocessors page, encrypted in transit, and lands in access-controlled inboxes protected by multi-factor authentication. The smallest number of people read it. Right now, that number is one.

Client work. Production code lives in your repositories, not ours. We work on least-privilege access you grant and can revoke, credentials live in secret managers rather than chat threads, and access is removed at handover. We don’t train AI models on your data, and engagement-specific security requirements (POPIA processing terms, data residency, audit trails) are agreed in the signed scope, where they belong.

If something goes wrong. We tell affected clients without undue delay, in line with POPIA’s notification requirements, with what happened, what it touched, and what we’re doing.

Found a vulnerability? Email hello@poursyrup.ai with the details. We read these fast, we won’t lawyer you for good-faith research, and we say thank you.

What we don’t claim. No ISO 27001, no SOC 2, not yet and not pretended. When a certification becomes the right move, it’ll appear here as a fact, not a badge wall.

syrup
146 Campground Road, Newlands, Cape Town · 7780
hello@poursyrup.ai
Pricing How it works Terms Privacy Subprocessors Security
© 2026 Syrup AI (Pty) Ltd. · Part of the Claude Partner Network AI that sticks.