Policy Library
Last Updated: 31 August 2026
This is the authoritative register of SyncMate's security, privacy and operational policies, maintained by WYHEN Pty Ltd (ABN 57 688 078 999). Every document is published here with its version number and effective date, so accounting firms, their clients and auditors can review the current set at any time without requesting copies.
All documents are Version 1.0, effective 31 August 2026, and are reviewed at least annually or after any material change to the service.
One signature covers them all — the Master Policy Attestation
Rather than signing and returning a separate acknowledgement for every document, a single Master Policy Attestation incorporates the whole register by reference — including documents added later. Signing (or electronically accepting) it once binds the signatory to the whole framework.
The attestation is rolling: it automatically covers later versions that make editorial, clarifying or strengthening changes. A fresh signature is only required where a change materially increases the signatory's obligations, where a signatory's access level changes materially, or at the 12-month annual re-attestation point for personnel. Every change is published here with a version number, effective date and change note, and attesting customers are notified by email at least 14 days before it takes effect.
The same attestation is used for both purposes: personnel sign it before they are granted any access to systems or customer data, and customers, firms and auditors sign it once to confirm they have received and reviewed the framework.
The register
| Ref | Policy | Summary | Documents |
|---|---|---|---|
| A1 | Service Level Agreement | 99.5% availability target, P1–P4 response and resolution targets, incident notification, service credits. | Read · Download |
| A2 | Security & Privacy Training Programme | Induction, annual refresher, quarterly phishing and secure-development training, with attendance records. | Read · Download |
| A3 | Development Process & Standards | Secure SDLC mapped to OWASP SAMM/ASVS, code review, dependency scanning, Row-Level Security enforcement. | Read · Download |
| A4 | Risk Management Policy & Register | 1–25 likelihood/impact scoring, treatment options, review cadence, and the current risk register. | Read · Download |
| A5 | IT Security Risk Assessment Methodology | Eight-step assessment process aligned to ISO 27005 and NIST SP 800-30. | Read · Download |
| A6 | Vulnerability Management Policy | Discovery sources, severity classification, and remediation SLAs (Critical 24h, High 7 days). | Read · Download |
| A7 | Threat Intelligence & Threat Assessment | STRIDE threat modelling, weekly advisory triage, and the current threat assessment. | Read · Download |
| A8 | Dev / Test / Prod Environment & Release Framework | Environment isolation, data separation, promotion gates, rollback, and change records. | Read · Download |
| A9 | Data Protection & Confidentiality Statement | Binding confidentiality, credential-handling, device-security and incident-reporting obligations for all personnel. | Read · Download |
| A10 | Exit, Data Destruction & Litigation Hold | Self-service export, deletion timelines, backup age-out, certificate of destruction, litigation hold. | Read · Download |
| A11 | Business Continuity & Disaster Recovery Plan | RPO 24h / RTO 1 business day, backup arrangements, failure-scenario responses, annual restore testing, key-person succession. | Read · Download |
Evidence of attestation
WYHEN maintains a record of who has attested, to which register version, and on what date. Signed attestations are retained for the duration of the relationship plus seven years, and the attestation record is available to customers and auditors on request as evidence that the control operates.
Related documents
See also our Trust & Security overview, the Security Statement, and the downloadable DPA template.
Questions or requests
To request a countersigned attestation, an executed DPA, or any supporting evidence, email contact@wyhen.com.au. We aim to respond within one business day.