Third Party Index

Snapshot 43645

Document
Security page
URL
https://security.synthesia.io/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
107116 bytes
SHA-256 (raw)
e9e32158633c0243a0959aa6d4005bed8080752b92d8555399372333e6833959
SHA-256 (normalized text)
7c46e2fc3294c5b26f71edcdfacae37203c84beecdf8f0738ac72df789e8cdad

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Synthesia
Synthesia allows you to create videos directly in a web browser. Simply select an actor, type in the text and use AI to generate your video without the need for actors, film crew or expensive equipment and post-production. You can create stunning business videos in minutes.
[email protected]
Privacy PolicyOpens in new tab
As a company pioneering this new kind of media, we’re aware of the responsibility we have. It is clear to us that artificial intelligence and similarly powerful technologies cannot be built with ethics and security as an afterthought. They need to be front and centre and an integral part of the company. This is reflected in our SOC2 report, our company policies and in the technology we are building. It is also the reason why we are an active member of Content Authenticity Initiative which was started by Adobe in 2019.
See this pageOpens in new tab for more details on our commitment to ethics and our 3Rs framework (Review, Report, and React).
See also a narrative description of our Security PracticesOpens in new tab.
To report any adverse impacts or concerns related to Synthesia AI systems, please use this formOpens in new tab.
For more details on processing of personal data, see our Data Processing AgreementOpens in new tab.
We are SOC2 Type II compliant and fully certified within ISO/IEC 27001:2022, ISO/IEC 27701:2019, and ISO/IEC 42001:2023.
Please also see our public AI Governance PracticesOpens in new tab page for more information.
Controls
Compliance
ISO/IEC 42001:2023
ISO/IEC 27001:2022
ISO/IEC 27701:2019
SOC 2 Type II
GDPR
UK Cyber Essentials
Resources
View all
Reports
Futuresafe: Synthesia's 2025 Responsible Creation Report
Certificates
Synthesia-2026 - Type 2 SOC 2
View 4 more
Assessments
Synthesia_2026_Penetration_Test_Executive_summary_Report.pdf
Synthesia_2026_Penetration_Test_Report.pdf
Data Protection Impact Assessment
AI Impact Assessment
View 1 more
Questionnaires
CAIQv4.0.2 STAR Security Questionnaire
SIG Lite questionnaire
AI Governance FAQ
Higher Education Community Vendor Assessment Toolkit
Diagrams
Data flow & Architecture Diagrams
General
Synthesia Assistant Security Data Privacy Overview
AI Screen Recorder - Security Overview.pdf
Roleplay Sessions Security Privacy and Data Handling Overview
Personal Avatars - Security Privacy Data Handling Overview
View 2 more
Policies
Access Control Policy
Anti-discrimination Policy
Anti-harassment Policy
Asset Management Policy
View 15 more
Customer Templates
Scaling Avatar's Responsibily - Template Avatar Use Policy
Scaling AI Avatars Responsibly - Template Avatar Governance Framework and Policy Template
FAQ
Data collected
Video data of a person to create a custom avatar
Voice audio data of a person to create a custom voice
Incidental PII as part of video scripts
Music and image assets uploaded as part of the video generation process
Employee personally identifiable information (name, email address, IP address)
Updates
View all
Compliance
SOC 2 Type II Report — 2026
Published July 28, 2026
Synthesia's 2026 SOC 2 Type II report is now available in our Trust Center.
The report covers the Trust Services Criteria for Security, Availability, Confidentiality, and Privacy — expanding our scope from prior years to include the Availability, Confidentiality and Privacy, categories. The examination was conducted by A-LIGN for the period April 7, 2025 to June 1, 2026, and reflects an unqualified opinion on both the design and operating effectiveness of controls.
Customers and prospects can request a copy from this page.
General
Synthesia
Published December 19, 2025
We’re proud to announce that Synthesia has successfully achieved ISO/IEC 27701:2019 certification — the leading international standard for Privacy Information Management Systems (PIMS). This certification confirms that our controls for handling and protecting personal data meet rigorous global requirements for both PII Controllers and PII Processors, as validated by A-LIGN with zero nonconformities during the Stage 2 audit.
ISO 27701 extends our existing ISO/IEC 27001 Information Security Management System and demonstrates our mature, end-to-end governance of privacy across all processes involved in the secure and privacy-respecting development, delivery, and operation of Synthesia’s AI-driven video platform. The certification scope includes all assets, technologies, personnel, and business processes supporting our platform, including the responsible development and use of AI systems for avatar creation and voice cloning .
This achievement builds on our existing ISO/IEC 27001 and ISO/IEC 42001 certifications, reinforcing Synthesia’s ongoing commitment to continuous improvement, transparency, and the highest standards of security and privacy. Customers can rely on Synthesia to safeguard personal data with independently verified controls aligned with international best practices.