How Sydnee helps protect your client work
Learn how Sydnee protects team sign-in, separates access, and gives your company clear control over client work.
Your clients may share files, messages, Tasks, and form answers with your company. They trust you to keep that work with the right people. Sydnee gives you clear ways to protect each sign-in, each client account, and the work inside it.
You do not need to run a security system on your own. Sydnee handles the sign-in and session checks. You choose who belongs in your workspace, which client accounts they can open, and what clients can see.
Technical security details for IT teams
Transport and files. The Sydnee team app and API use HTTPS (TLS). Current browser file uploads and public API uploads request server-side AES-256 encryption from Amazon S3. Before it issues a client file link, Sydnee checks workspace, account, and file access. The signed preview or download link expires after one hour. A team member can also create a public link for one file. Anyone with that active link can download the file without signing in.
Sign-in and sessions. Team passwords are hashed with bcrypt. Team members can turn on multi-factor authentication (MFA) with an authenticator app. Sydnee encrypts the MFA setup key and stores one-time backup codes as hashes. Members can review and end active sessions. A password reset ends existing sessions. Clients sign in with one-time email codes that expire under the workspace's sign-in rules. Sydnee stores hashes of portal codes and session tokens. It limits repeated attempts and checks each session's expiry and account access. Owners can set portal code and session lifetimes. Owners and admins can end a client session.
Access and integrations. For team and portal access, Sydnee checks workspace membership, client-account assignment, and the item's visibility. The visibility rules vary for Files, Requests, and Tasks. With Encrypt Answer on, Sydnee encrypts a Request Short Text answer with AES-256-GCM before it is saved. It masks the answer in normal views. API keys can reach the whole workspace, so keep them in a secret store. Owners and admins can revoke them. Custom webhooks require HTTPS. Each request has an HMAC-SHA256 signature so the receiving service can verify the sender.
Security works in layers
Sydnee does not rely on one setting to protect all client work. It uses several layers:
- Sign-in protection checks who is entering the team workspace or client portal.
- Workspace roles decide who can manage company-wide settings.
- Account access decides who can open each client account.
- Visibility settings decide which Files, Requests, and Tasks a person can see.
These layers give a company owner more control. A person can have the right workspace role without gaining access to every client. A client can enter their account without seeing the team's private work.
Your team and clients sign in separately
Team members sign in to the team workspace with their own email and password. Each person should have their own team account. This keeps their access and account history separate from everyone else.
Client contacts use your branded portal. They sign in with a code sent to their email.
The company owner can set how long client codes and sessions last under Company Settings β Client Portal Security. Owners and admins can review valid client sessions and end a session when access needs to stop. Set client portal sign-in rules explains the choices.
Access to one client account does not open another account. This helps you keep each client relationship in its own place as your company grows.
Add another check to team sign-in
Each team member can turn on multi-factor authentication, or MFA. MFA asks for a six-digit code after the password. The code comes from an authenticator app, which is often on the person's phone.
MFA matters because a password may be guessed, reused, or shared by mistake. A person who learns the password would still need the current code to finish signing in.
Sydnee also gives the team member a set of one-time backup codes. These codes can help if the phone with the authenticator app is lost or replaced. Save them in a password manager or another safe place that the team member can still reach.
The QR code, setup key, MFA codes, and backup codes are private. Never send them in chat, email, a support request, or a screenshot.
For setup and recovery steps, read Change your password and use MFA.
Stay in control of signed-in browsers
After a team member signs in, Sydnee starts a browser session. This session lets the person move between pages without entering a password each time.
Sydnee checks the session when the browser asks for workspace data. Each session has an end date and can be ended before then.
Each team member can review their active browser sessions under Personal Settings β Security. They can end a session from a device they no longer use or know. Sydnee asks for a fresh check before it ends that session.
The same page shows Recent Account Protection History. It lists personal sign-in, password, and MFA events. The history window follows the highest paid plan the person can access across their active workspaces. This gives each person a place to check activity that does not look right.
Read Review account security activity to learn what the events mean and how to end a session.
Give each person only the access they need
A company owner or admin controls two different choices for each team member:
- Their workspace role controls company-wide settings and actions.
- Their account access controls which client accounts they can open.
Keeping these choices separate helps a growing team. For example, a team member can work with two clients without seeing every account in the company.
Inside an account, Files, Requests, and Tasks have more visibility settings. These settings help your team share the work a client needs while keeping team-only work private.
For details about these choices, read Team roles and access and Client invites and portal access.
How Sydnee handles error reporting
When something goes wrong, Sydnee may create a technical error report. These reports help the team find and fix bugs.
Sydnee filters each report. The filter keeps out passwords, sign-in keys, access tokens, signed links, request text, and other client data. Sydnee sends even less detail if for some reason our system does not know if there is personal data in the error report.
A simple security routine for your company
You can start with a few habits:
- Give each team member their own sign-in.
- Choose the right workspace role and client accounts for each person.
- Ask team members to turn on MFA and save their backup codes.
- Check client visibility before you share Files, Requests, or Tasks.
- Remove account access when a person no longer works with that client.
- Review active sessions and recent security activity from time to time.
For client access, review valid client portal sessions. That list shows sign-ins that can still open the portal; it is not an online activity report.
These steps help your company stay in control without adding a lot of work to each day.
What if something does not look right?
If you see a sign-in or session you do not know:
- Open Personal Settings β Security.
- Check the event time, device, country, and network address.
- End the active session you do not know.
- Change your password.
- Turn on MFA. If MFA is already on, make a new set of backup codes.
- Open Help & Support if the activity still looks wrong.
Send the event type and time shown on the page. Keep passwords, MFA codes, backup codes, QR codes, setup keys, and session details private.
Related security guides
- Change your password and use MFA
- Review security activity and active sessions
- Set client portal sign-in rules
- Review and end client portal sessions
- Manage team roles and account access
- Manage client invitations and portal access
Next, set up your profile and branded portal before you invite clients.
π Next: Make Sydnee yours