Security posture
Most vendor security pages are a wall of badges that a reviewer has to disprove. This one lists the controls that are in place, the ones that are partial, the ones that are absent, and the residual risk we accepted and why. It is faster to read than to discover.
35
findings identified in assessment
86%
remediated and validated (30 of 35)
5/5
critical findings closed. High: 11 of 12
Assessment SNYTE-SEC-2026-001 · 13 February 2026 · figures transcribed from the internal report
Controls
Pick a domain. Nothing is filtered out: gaps sit in the same list as the controls that work.
JWKS-based RS256 validation against WorkOS AuthKit.
An unrecognised auth type returns 503 rather than allowing the request.
TOTP, with session expiry and revocation.
IP-based rate limiting that falls back to in-memory when Redis is down.
No SAML or SCIM endpoints are mounted. Directory sync is not available; users are provisioned through WorkOS.
Residual risk
Transcribed from the assessment’s own residual-risk table rather than summarised.
| Item | Level | Mitigation |
|---|---|---|
| CSP allows unsafe-inline | Medium | Required by the framework's inline bootstrap; external script origins remain blocked. |
| Kubernetes secrets not encrypted at rest | Medium | Cluster-level configuration, documented as a deployment requirement. |
| Session IP mismatch is logged, not enforced | Low | Detection is active; enforcement deferred pending a UX decision. |
Not claimed
Listed here so a reviewer does not spend a call establishing them.
Controls are built against SOC 2 criteria and the assessment above is independent of that. Snyte does not hold a SOC 2 Type I or Type II report and does not claim one.
There is no SLA document, and the Terms of Service disclaim an availability commitment. Any uptime undertaking would have to be negotiated into a contract.
Every deployment path in the repository is self-managed: Kubernetes manifests or Docker Compose, running in your infrastructure.
A penetration testing plan exists in the repository; results are not published here.
Paperwork
The full data processing agreement, subprocessor list, and acceptable use policy are published, not gated behind a call.
Security review
Send a questionnaire, or ask for the full assessment report and the incident response plan. Both exist and both can be shared under NDA.
Start a security review