Skip to content
SyntasaBrief our team
PlatformMissionEnterpriseCustomersPartnersTrust CenterInsights
Trust Center

Security, sovereignty, and accreditation.

Where Syntasa runs, what it depends on, and what has been accredited. Zero trust is only enforceable when you can see your AI — this is where you see ours.

Deployment models

Syntasa deploys as a single codebase across four substrates. Software provenance is identical in all four; only the promotion path differs.

ModelBoundaryUpdate path
CloudCustomer's cloud tenancy, region, and encryption keys. Syntasa holds no standing access.Customer-approved releases
HybridClassified or regulated processing on-prem; elastic workloads in the customer's cloud tenancy.Split: per-substrate approval
On-premCustomer data center, customer hardware, customer network controls end to end.Offline media or controlled channel
Air-gappedNo route to the internet at any time. Google Distributed Cloud certified. All dependencies vendored; no callbacks, no telemetry, no external model APIs.Verified offline media, customer-controlled promotion
Design baseline — air gap

Air-gapped operation is the design baseline. The other three models are relaxations of it — not the reverse.

No route to the internet at any time. All dependencies vendored. No callbacks, no telemetry, no external model APIs. Google Distributed Cloud certified; deployed in the nation's highest classified environments.

Zero-trust principles

Identity

Every request — human or agent — is authenticated against the customer's identity provider. There are no shared service accounts and no Syntasa-held credentials in production.

Privilege boundaries

Least privilege is enforced at the data, model, and agent layers independently. An agent's authority is a declared, reviewable artifact — it cannot exceed the identity that invoked it.

Auditable data movement

Every read, transformation, and export is logged with actor, time, and justification. Audit records are append-only and exportable to the customer's SIEM.

Ingest-time governance

Governed at ingest: lineage, classification handling, and policy enforced from the moment data arrives, not after.

Customer boundary — every request path
Step 1
Your identity provider
Authenticates every human and agent request
Step 2
Policy enforcement
Least privilege at data, model, and agent layers independently
Step 3
Data · Models · Agents
Scoped access; agent authority never exceeds its invoker
Append-only audit log — actor · time · justification→ exports to your SIEM

Contained by design. Observable by default.

Agent containment

Autonomous agents change the failure model. When an agent holds credentials and a route out, the agent's reach — not your policy — becomes the effective boundary of your data. The industry's recent agent incidents share one shape: broad authority, standing credentials, and no perimeter between the agent and the outside world.

Containment by architecture

An agent inside the perimeter cannot leak what the perimeter does not release.

Syntasa agents run inside the same sealed boundary as the data, under the same controls as any human operator. Containment is a property of the architecture, not an instruction the agent is trusted to follow.

Declared authority
What an agent may do is a reviewable artifact — never more than the identity that invoked it.
Credentials that expire
Identity-bound, time-boxed, scoped to the task. No standing credentials for agents to inherit.
No route out
Agents act only inside the perimeter. In air-gapped deployments there is no outside to reach.
Causality on record
Every action logged with its chain of whys — the data, model, and policy behind each decision.

AI observability

Containment answers what an agent can reach. Observability answers what it actually did. Syntasa gives full visibility into what models and agents do with data — every model, pipeline, job, query, and service on one governed plane, with the causal chain behind each output preserved.

Model behavior
What each model consumed, what it produced, and on which version of the data.
Agent activity
Every action an agent took, under whose identity, within which declared authority.
Data lineage
Raw source to decision, traceable in both directions and exportable to your SIEM.
Cost attribution
Compute and spend mapped per workload, visible before the bill arrives.

Accreditations, with scope

FEDRAMP HIGHFedRAMP High (Class D under CR26, effective July 2026). Scope: the full Syntasa platform as deployed for federal customers.
FEDERAL ATOsAuthorities to Operate held with U.S. federal agencies, including deployments in the nation's highest classified environments. Specific agencies and networks are not named publicly.
GOOGLE DISTRIBUTED CLOUDCertified for air-gapped delivery. Syntasa is a Google Cloud Premier Partner with the Data Analytics Specialization.
In production since 2014 · US · UK · EU

Jurisdiction and data handling

Customer data is processed only within the customer's chosen jurisdiction and boundary. Syntasa operates deployments in the US, UK, and EU. Data residency is structural: the platform has no mechanism to move customer data to Syntasa infrastructure, because no such infrastructure sits in the data path.

Syntasa personnel access production systems only under customer-granted, time-boxed, logged credentials. Support does not require data access; where diagnostic data is shared, it is customer-initiated and customer-reviewed.

One sentence version: your data never touches our systems.

Disclosure policy

Security researchers may report suspected vulnerabilities to security@syntasa.com. We acknowledge reports within two business days, and we do not pursue action against good-faith research conducted within scope.

Customers under active agreement receive notice of confirmed, in-scope security incidents per contractual terms — typically within 24 hours of confirmation.

Need this in writing?

Accreditation letters, architecture documentation, and security questionnaires are available under NDA.

Request a technical briefing