Security and privacy

Built for people who do not share an employer

Joining a workspace never exposes anything you did not choose to share, and every one of these rules is enforced on the server, never by hiding things in the app.

  • Private by default

    Every project is private in every workspace until you share it, one workspace at a time.

  • Your code stays yours

    DevSyncora's servers never fetch source code: the GitHub App's read access exists only because GitHub sends push events to apps with it, and DevSyncora never uses it to read code. Agents you run through the Bridge work on your own computer, only in folders you link.

  • Enforced on the server

    Nothing is hidden only in the app: every rule is checked on the server, down to what the realtime connection carries.

  • Nothing is recorded

    Voice is never recorded and AI voice audio is never stored. Push to talk is the default.

Workspaces are sealed from each other

DevSyncora puts people from different employers into one room, so joining a workspace exposes nothing on its own.

  • Everything in a workspace is checked against your membership first. To anyone outside, a workspace simply does not exist.
  • Roles come from one permission rulebook: nobody changes their own role, admins only manage people below them, and the owner can never be removed.
  • Invites are random codes with an expiry and a use limit, and they can be revoked at any time.
  • Nothing ever puts you inside a workspace without you choosing to walk in.

The world only knows what you may see

The 3D studio follows the same rules as the rest of the app, right down to the live connection.

  • Stations, sticky notes, shared items and AI workers are filtered per person: your connection never carries anything you are not allowed to see.
  • The server is in charge of the world. Movement, seats, games and scores are checked there, so a modified app cannot cheat or peek.
  • Changing a project's visibility applies to its whole history, not just to new activity.

Closed offices keep conversations in

An office door is enforced by the server, not by the door model you see.

  • While an office is not open, chat and voice do not cross its walls: people inside only hear each other.
  • PINs are stored only as a salted hash, never shown or logged, and a few wrong tries lock the keypad for a while.
  • Workspace admins get in by changing the door or giving themselves a key, and both are written to the audit log. There is no silent master key.
  • Being inside is sticky: locking a door never traps or throws anyone out.

Sign-in and sessions

You sign in with GitHub. DevSyncora stores no passwords.

  • Access tokens last 15 minutes and are kept in memory, never in browser storage.
  • Refresh tokens are stored only as hashes and change on every use; reusing an old one signs that device out everywhere.
  • Your account's security settings list every signed-in device, and you can sign any of them out at once, world sessions included.

Secrets and integrations

What DevSyncora holds for you is locked away and never handed back out.

  • Provider tokens are encrypted (AES-256-GCM) and never appear in a response or a log.
  • Webhooks are verified by signature before anything in them is trusted, and only the metadata of what happened is kept, never the raw payload.
  • From Linear, only titles, identifiers, states and labels are kept: never descriptions, comments or email addresses.
  • Connecting GitLab, Jira, Slack or Discord can only be finished by the person who started it, and their grants and channel links are encrypted and never handed back.
  • Slack and Discord only receive moments every member of the workspace may see, posted only to the providers' own webhook addresses with mentions turned off.

Voice and AI voice

Talking should feel like being in the room, with none of the recording.

  • Spatial voice is for members only, and your microphone is only requested the first time you talk.
  • AI voice audio is never stored. Standard voice uses your browser's own speech recognition; HD voice sends audio only to the speech providers that transcribe it and speak the reply.
  • Transcripts are kept as text and only the person who spoke can read them. What an agent can see is limited to what you can see.

The DevSyncora Bridge

The Bridge runs your own Claude Code or Codex on your own computer.

  • Your Claude Code or Codex login is never read or sent anywhere: your provider bills you directly.
  • Every device is paired with a code you approve in the app. Nothing approves itself.
  • Agents only work in folders you link, within the limit you set for each folder, and absolute paths never leave your computer.
  • The Bridge never turns off your AI tool's own permission prompts.
  • A run you start from DevSyncora sends back what the agent says, the commands it runs and a diff of what it changed, so you can follow it. Your runs are private to you unless you share them with a workspace.

Safety tools

Everyone can protect themselves, and every workspace can be moderated.

  • Block someone and they stop reaching you everywhere: messages, knocks, notes, voice and screen shares. They are never told.
  • Report a person or something they wrote to the workspace admins. The reported person never sees the report.
  • Admins can mute someone in chat, take them out of the room for a while or ban them, and every action is audited.

Your data

Your account is yours to take with you or to delete.

  • Export a copy of everything that is yours: profile, projects, notes, messages you sent, game results and more. Never what other people wrote.
  • Deleting your account erases your profile, integrations and their tokens, projects, notes, messages you sent, agent runs, AI voice transcripts, devices and uploads.
  • The audit log records security-relevant actions without secrets or private project details. Its IP addresses are deleted after 12 months.
  • No analytics, advertising or tracking, on this website or in the app.

Reporting a vulnerability

Please report security issues privately to hello@syncfac.com, never in public. Tell us what you found and how to reproduce it, and give us a reasonable time to fix it before you share it. How we handle personal information is in the Privacy policy.

A persistent 3D studio for developers and the people they build with.

In development, not released yet

© 2026 SyncFac (Pty) Ltd. Real activity builds the world.