Trust
Security & Control
Every Syntheon system runs inside a control model that is defined before the first line of code. This is what an agent can reach, what it can do on its own, and what it can never do without a person.
The control model
Authority is assigned before anything is built
The same five questions are answered for every workflow we deploy. The answers are written into the system, not into a policy document beside it.
- 01
What the agent can access
Scoped, read-only connections to named source systems. Access is granted per system and per field, not per user account.
- 02
What it can do unattended
Retrieve, extract, interpret policy, draft, prepare and route. Everything reversible.
- 03
What requires human approval
Any action that changes a customer relationship, accepts risk, or leaves your organisation. Nothing irreversible happens without a named person approving it.
- 04
What is logged
Every retrieval, every decision, every action, every approval, with the inputs used and the policy applied, in a structured trail designed for regulatory review.
- 05
Who can override it
Named roles with documented authority. Overrides are themselves logged, with the reason recorded.
A worked example
One enhanced due diligence review, step by step
The agent prepares the case completely and then stops at the decision it is not permitted to make. A named reviewer decides, and the trail records both.
Case walkthrough
Enhanced due diligence review, corporate customer
- Agent
Retrieves from three named source types
Core banking record, corporate registry extract and adverse media search. Read-only, per field, within the agreed scope.
Audit entry: Sources, queries and timestamps recorded
- Agent
Applies the policy clause
EDD policy section 4.2, beneficial ownership below the stated threshold. The clause used is cited, not summarised from memory.
Audit entry: Policy version and clause reference recorded
- Agent
Drafts the assessment
A structured EDD note with findings, unresolved gaps and the evidence behind each statement. Reversible, unpublished, visible only inside the case.
Audit entry: Draft version stored with inputs used
- ControlNot permitted without approval
Reaches a decision it may not make
Accepting the relationship at elevated risk changes the customer relationship and accepts risk on behalf of the institution. The agent stops.
Audit entry: Stop reason and required approval level recorded
- Control
Routes to a named reviewer
The case is assigned to the compliance officer holding documented authority for this decision, with the draft and the evidence attached.
Audit entry: Assignment, recipient and time recorded
- Reviewer
Reviewer approves with a rationale
A person accepts, amends or rejects the recommendation and states why. The decision is theirs; the preparation was not.
Audit entry: Approver identity, decision and rationale recorded
- Control
Case closed with a complete trail
The file can be reconstructed end to end: what was read, which policy applied, what was drafted, what was refused, who decided.
Audit entry: Immutable case trail exported for review
Deployment and data
The conditions the model runs in
- Website delivery and data residency
- This website is delivered through a global content delivery network, so pages may be served from an edge location outside the EU. No client data is processed here. Client systems and client data are a separate matter: production deployments and any client data we process run in EU regions, and data residency is agreed per engagement and recorded in the documentation for that system.
- Data boundary
- Client data is segregated per engagement. We do not repurpose it for training, marketing or benchmarking.
- Encryption
- In transit using TLS 1.2 or higher. At rest on managed storage backed by AES-256.
- Least privilege
- Access is scoped to named individuals, reviewed regularly, revoked at the end of an engagement. Multi-factor authentication is required on all production and administrative accounts.
- Confidentiality
- Treated as confidential. A mutual NDA is available before detailed disclosure.
- Frameworks
- Delivery practices are aligned with recognised information security frameworks, including ISO/IEC 27001 controls and the governance expectations of the EU AI Act. We do not currently hold third-party certification against these frameworks and do not claim otherwise.
- Responsible disclosure
- Report a suspected security issue to contact@syntheonai.se. We acknowledge reports promptly and work with reporters in good faith.
Last updated: 13 August 2026
See how this would apply to one of your workflows
Two minutes. We identify where an agentic system could assist, automate or escalate the work, and where human control should stay.
Syntheon AI AB · Org. nr 559329-3128 · c/o Bluerock AB, Mailbox 113, 111 73 Stockholm, Sweden
