Security
Most vendor security pages are a wall of badges a reviewer has to disprove. This one lists the controls that are in place, the ones that are partial, the ones that are absent, and the residual risk we accepted and why. It is faster to read than to discover.
Assessment SNYTE-SEC-2026-001 · 13 February 2026 · figures transcribed from the internal report
35
findings identified in the assessment
86%
remediated and validated (30 of 35)
5/5
critical findings closed. High: 11 of 12
Controls
Grouped by domain. Nothing is filtered out: the gaps sit in the same list as the controls that work.
5 controls, 1 not fully in place
JWKS-based RS256 validation against WorkOS AuthKit.
An unrecognised auth type returns 503 rather than allowing the request.
TOTP, with session expiry and revocation.
IP-based rate limiting that falls back to in-memory when Redis is down.
No SAML or SCIM endpoints are mounted. Directory sync is not available; users are provisioned through WorkOS.
4 controls, 2 not fully in place
Hierarchy enforced per route: admin > editor > viewer.
User ownership is verified on data access endpoints.
Postgres row-level security is enabled and FORCEd on the six decision_* tables, keyed on a request-scoped org GUC that fails closed when unset. Every other table relies on an application-level organization predicate. The migration describes itself as phase 1.
Quotas are modelled in the schema but nothing enforces them at runtime.
5 controls, 1 not fully in place
Statements run against the connected source. Results are not sampled or simulated.
Insight generation serialises query result rows into a prompt sent to whichever model provider is configured; the default is OpenAI. Natural-language translation sends schema rather than rows. OpenAI and Anthropic are both named on the subprocessor list.
Ollama is a first-class provider with completion, streaming, embeddings, and health checks. Point AI_DEFAULT_PROVIDER at a self-hosted model and no prompt, schema, or row leaves your network.
Data source credentials are encrypted with AES-256-GCM. This covers stored connection secrets, not whole-database encryption.
HSTS with preload in production, TLS required for database connections, WSS with origin validation.
3 controls, 1 not fully in place
Access, authentication, and security events are written and queryable per user, per organization, and system-wide.
Read and query APIs are complete; write coverage does not yet span every mutating endpoint.
The generated SQL is retained on the query record, so what ran can be read back.
3 controls, 1 not fully in place
Middleware covering SQL injection, XSS, command injection, and path traversal; parameterised queries throughout; HTML sanitised via bluemonday.
X-Frame-Options DENY, nosniff, strict-origin-when-cross-origin, no-store on API responses, and sanitised error bodies.
A CSP ships on every response, but script-src and style-src both allow 'unsafe-inline'. The statically rendered build cannot issue a per-request nonce for Next's bootstrap script. This is an accepted risk, recorded in the assessment.
3 controls, 1 not fully in place
Distroless API image, non-root users, multi-stage builds, resource limits on all containers.
Database, cache, and monitoring ports bound to localhost only.
Not configured by Snyte. etcd encryption is a cluster-level responsibility and is listed as a deployment requirement.
Not claimed
Listed here so a reviewer does not spend a call establishing them.
Controls are built against SOC 2 criteria and the assessment above is independent of that. Snyte does not hold a SOC 2 Type I or Type II report and does not claim one.
There is no SLA document, and the Terms of Service disclaim an availability commitment. Any uptime undertaking would have to be negotiated into a contract.
Every deployment path in the repository is self-managed: Kubernetes manifests or Docker Compose, running in your infrastructure.
A penetration testing plan exists in the repository; results are not published here.
Residual risk
Transcribed from the assessment’s own residual-risk table rather than summarised.
| Item | Level | Mitigation |
|---|---|---|
| CSP allows unsafe-inline | Medium | Required by the framework's inline bootstrap; external script origins remain blocked. |
| Kubernetes secrets not encrypted at rest | Medium | Cluster-level configuration, documented as a deployment requirement. |
| Session IP mismatch is logged, not enforced | Low | Detection is active; enforcement deferred pending a UX decision. |
Paperwork
Published, not gated behind a call. The full assessment report and the incident response plan also exist and can be shared under NDA.
Next
Walk through the product with the trace open, or start with the deployment model your security team will accept. Everything on this page is on the table.