Skip to content

Trust

Security & Control

Every Syntheon system runs inside a control model that is defined before the first line of code. This is what an agent can reach, what it can do on its own, and what it can never do without a person.

The control model

Authority is assigned before anything is built

The same five questions are answered for every workflow we deploy. The answers are written into the system, not into a policy document beside it.

  1. 01

    What the agent can access

    Scoped, read-only connections to named source systems. Access is granted per system and per field, not per user account.

  2. 02

    What it can do unattended

    Retrieve, extract, interpret policy, draft, prepare and route. Everything reversible.

  3. 03

    What requires human approval

    Any action that changes a customer relationship, accepts risk, or leaves your organisation. Nothing irreversible happens without a named person approving it.

  4. 04

    What is logged

    Every retrieval, every decision, every action, every approval, with the inputs used and the policy applied, in a structured trail designed for regulatory review.

  5. 05

    Who can override it

    Named roles with documented authority. Overrides are themselves logged, with the reason recorded.

A worked example

One enhanced due diligence review, step by step

The agent prepares the case completely and then stops at the decision it is not permitted to make. A named reviewer decides, and the trail records both.

Case walkthrough

Enhanced due diligence review, corporate customer

7 steps · 7 audit entries
  1. Agent

    Retrieves from three named source types

    Core banking record, corporate registry extract and adverse media search. Read-only, per field, within the agreed scope.

    Audit entry: Sources, queries and timestamps recorded

  2. Agent

    Applies the policy clause

    EDD policy section 4.2, beneficial ownership below the stated threshold. The clause used is cited, not summarised from memory.

    Audit entry: Policy version and clause reference recorded

  3. Agent

    Drafts the assessment

    A structured EDD note with findings, unresolved gaps and the evidence behind each statement. Reversible, unpublished, visible only inside the case.

    Audit entry: Draft version stored with inputs used

  4. ControlNot permitted without approval

    Reaches a decision it may not make

    Accepting the relationship at elevated risk changes the customer relationship and accepts risk on behalf of the institution. The agent stops.

    Audit entry: Stop reason and required approval level recorded

  5. Control

    Routes to a named reviewer

    The case is assigned to the compliance officer holding documented authority for this decision, with the draft and the evidence attached.

    Audit entry: Assignment, recipient and time recorded

  6. Reviewer

    Reviewer approves with a rationale

    A person accepts, amends or rejects the recommendation and states why. The decision is theirs; the preparation was not.

    Audit entry: Approver identity, decision and rationale recorded

  7. Control

    Case closed with a complete trail

    The file can be reconstructed end to end: what was read, which policy applied, what was drafted, what was refused, who decided.

    Audit entry: Immutable case trail exported for review

Deployment and data

The conditions the model runs in

Website delivery and data residency
This website is delivered through a global content delivery network, so pages may be served from an edge location outside the EU. No client data is processed here. Client systems and client data are a separate matter: production deployments and any client data we process run in EU regions, and data residency is agreed per engagement and recorded in the documentation for that system.
Data boundary
Client data is segregated per engagement. We do not repurpose it for training, marketing or benchmarking.
Encryption
In transit using TLS 1.2 or higher. At rest on managed storage backed by AES-256.
Least privilege
Access is scoped to named individuals, reviewed regularly, revoked at the end of an engagement. Multi-factor authentication is required on all production and administrative accounts.
Confidentiality
Treated as confidential. A mutual NDA is available before detailed disclosure.
Frameworks
Delivery practices are aligned with recognised information security frameworks, including ISO/IEC 27001 controls and the governance expectations of the EU AI Act. We do not currently hold third-party certification against these frameworks and do not claim otherwise.
Responsible disclosure
Report a suspected security issue to contact@syntheonai.se. We acknowledge reports promptly and work with reporters in good faith.

Last updated: 13 August 2026

See how this would apply to one of your workflows

Two minutes. We identify where an agentic system could assist, automate or escalate the work, and where human control should stay.

Syntheon AI AB · Org. nr 559329-3128 · c/o Bluerock AB, Mailbox 113, 111 73 Stockholm, Sweden