Policy Library

Last Updated: 31 August 2026

This is the authoritative register of SyncMate's security, privacy and operational policies, maintained by WYHEN Pty Ltd (ABN 57 688 078 999). Every document is published here with its version number and effective date, so accounting firms, their clients and auditors can review the current set at any time without requesting copies.

All documents are Version 1.0, effective 31 August 2026, and are reviewed at least annually or after any material change to the service.

One signature covers them all — the Master Policy Attestation

Rather than signing and returning a separate acknowledgement for every document, a single Master Policy Attestation incorporates the whole register by reference — including documents added later. Signing (or electronically accepting) it once binds the signatory to the whole framework.

The attestation is rolling: it automatically covers later versions that make editorial, clarifying or strengthening changes. A fresh signature is only required where a change materially increases the signatory's obligations, where a signatory's access level changes materially, or at the 12-month annual re-attestation point for personnel. Every change is published here with a version number, effective date and change note, and attesting customers are notified by email at least 14 days before it takes effect.

The same attestation is used for both purposes: personnel sign it before they are granted any access to systems or customer data, and customers, firms and auditors sign it once to confirm they have received and reviewed the framework.

Read the Master Policy Attestation

The register

RefPolicySummaryDocuments
A1Service Level Agreement99.5% availability target, P1–P4 response and resolution targets, incident notification, service credits.Read · Download
A2Security & Privacy Training ProgrammeInduction, annual refresher, quarterly phishing and secure-development training, with attendance records.Read · Download
A3Development Process & StandardsSecure SDLC mapped to OWASP SAMM/ASVS, code review, dependency scanning, Row-Level Security enforcement.Read · Download
A4Risk Management Policy & Register1–25 likelihood/impact scoring, treatment options, review cadence, and the current risk register.Read · Download
A5IT Security Risk Assessment MethodologyEight-step assessment process aligned to ISO 27005 and NIST SP 800-30.Read · Download
A6Vulnerability Management PolicyDiscovery sources, severity classification, and remediation SLAs (Critical 24h, High 7 days).Read · Download
A7Threat Intelligence & Threat AssessmentSTRIDE threat modelling, weekly advisory triage, and the current threat assessment.Read · Download
A8Dev / Test / Prod Environment & Release FrameworkEnvironment isolation, data separation, promotion gates, rollback, and change records.Read · Download
A9Data Protection & Confidentiality StatementBinding confidentiality, credential-handling, device-security and incident-reporting obligations for all personnel.Read · Download
A10Exit, Data Destruction & Litigation HoldSelf-service export, deletion timelines, backup age-out, certificate of destruction, litigation hold.Read · Download
A11Business Continuity & Disaster Recovery PlanRPO 24h / RTO 1 business day, backup arrangements, failure-scenario responses, annual restore testing, key-person succession.Read · Download

Evidence of attestation

WYHEN maintains a record of who has attested, to which register version, and on what date. Signed attestations are retained for the duration of the relationship plus seven years, and the attestation record is available to customers and auditors on request as evidence that the control operates.

Related documents

See also our Trust & Security overview, the Security Statement, and the downloadable DPA template.

Questions or requests

To request a countersigned attestation, an executed DPA, or any supporting evidence, email contact@wyhen.com.au. We aim to respond within one business day.