For IT and Security

Governance that fits your perimeter
and your audit cycle.

If you are the person who owns the platform inside the perimeter and the controls that the auditor attests to, this page is the technical evaluation. Syntheka runs self-hosted. The keys stay yours. The audit trail is append-only and hash-chained. The integrations are MCP-native. Honest on what we have and what we do not yet have.

Syntheka is built for that question. This page is the evaluation checklist we use with IT and Security leadership. Honest on what we do, what we don't do, and where we are not yet ready for your environment.

Why this matters to IT and Security

The question is not “can it integrate” but “can it run inside the perimeter under the controls you already attest to.”

An IT and Security leader evaluating AI agent platforms is not asking about feature checklists. The question is where credentials live, where data lives, what the audit trail looks like, and whether the platform can be deployed under the controls you already attest to — SOC 2, ISO 27001, the internal control framework, the regulated environment.

What Syntheka actually does for IT and Security

Deployment topology and integration surface.

Syntheka runs in three deployment topologies and integrates with the systems you already have. The integration surface is MCP-native; you can write your own integrations if you need to. The platform runs without any external network access if you need it to.

Deployment

Self-hosted Docker Compose

One-command bootstrap in your data center or private cloud. Data stays in your network.

Your team owns upgrades. The platform runs as a Docker Compose stack with the standard observability surface (OpenTelemetry, Prometheus, Loki, Grafana).

Deployment

Private cloud tenant

Runs in your AWS, GCP, or Azure tenant, in the region you choose.

Equivalent data sovereignty with the cloud provider's controls layered in. IAM, KMS, audit logs, and key custody stay with your team.

Deployment

Air-gapped

Runs without any external network access, including for LLM inference.

Model inference happens locally or via a private inference server. Audit trails are local. Updates are tarball-based. No egress required to operate.

Integrations

MCP-native ERP / CRM

MCP-native integrations for SAP, Salesforce, NetSuite, Procore, and the systems you already have.

SAP via OData / IDoc / BAPI / Events / CDC; Salesforce, HubSpot, Zoho; Oracle, Microsoft Dynamics 365, Sage, Foundation, QuickBooks Online.

Identity

Identity federation

OIDC, SAML, LDAP, Active Directory. Short-lived tokens; mTLS between services.

Your identity provider remains the source of truth for users and roles. The platform enforces roles server-side; no client-side trust.

Observability

OpenTelemetry-native

OpenTelemetry traces, Prometheus metrics, Loki logs, Grafana dashboards.

Audit trail export as structured JSON for your SIEM. Hash chain validation as a callable API endpoint. Upgrade events in the same audit log as agent actions.

What Syntheka does NOT do

Honest boundaries for the IT and Security conversation.

If any of these are required for your evaluation, Syntheka is not the right vendor today. We will tell you, and refer you elsewhere if we can.

The IT and Security evaluation checklist

Twelve questions to ask of any AI agent vendor.

Use these against any vendor, including us. If a vendor cannot answer them clearly, treat that as the answer.

  1. Where do credentials live — your perimeter, or vendor-managed?
  2. Can the vendor's staff access our systems of record with their own credentials, or only with credentials we control?
  3. Is the audit trail append-only with a hash chain, and can we verify chain integrity on demand?
  4. Do you record bi-temporal timestamps (transaction time + valid time), or only one of them?
  5. What is the deployment topology — Docker Compose in our network, our cloud tenant, or air-gapped?
  6. Can the platform run without any external network access, including for LLM inference?
  7. How do you handle multi-entity / multi-region writes — refuse by default, or allow?
  8. What is your patch cadence, and what is the customer-facing change log?
  9. What is your model of credential rotation — short-lived tokens, mTLS, both?
  10. Is the audit log exportable as structured JSON for our SIEM / audit analytics tooling?
  11. What is the upgrade path — rolling, blue-green, or maintenance window — and do upgrades require downtime?
  12. What is the exit path — data portability, audit log export, credential revocation, hash chain continuation or verifiable bridge?
Pricing for IT and Security

Three numbers that matter.

Syntheka's pricing is published, not quoted. There are no per-action variable surprises because there are no per-action variables in the price.

TierPriceFits
Starter$500 / monthOne team, one workflow, one site
Professional$2,000 / monthMulti-workflow, multi-site, multi-approver
EnterpriseQuote (custom)Self-hosted, air-gapped, regulated environment

A fixed-fee pilot is $1,500 for one site, 60 days, up to two workflows. The pilot pricing is honored for the first three customers.

Enterprise tier includes the technical evidence pack: deployment topology review, integration security review, hash chain validation report, audit log export schema, and the exit path documentation.

How to start

The IT and Security path through the pilot.

Most IT and Security teams we work with run a 60-day pilot on one integration (SAP, Procore, or Salesforce), then expand based on measured results. The pilot ends with a technical evidence pack, not a swap.

  1. Week 1: Deployment. Syntheka stands up in your infrastructure (Docker Compose or your cloud tenant). One-command bootstrap. Identity federation with your IdP.
  2. Weeks 2-3: Integration. Connect one system of record (SAP, Procore, Salesforce). MCP-native integration takes a day for the first integration. Audit log export to your SIEM configured.
  3. Weeks 4-5: Configuration. Configure one approval DAG for the workflow in scope. Set up the rule set, the approver chain, the SoD enforcement, the three-way reconciliation expectation.
  4. Weeks 6-7: Pilot run. The agent takes a small set of actions. Every action goes through the approval DAG. Every approval is recorded. Every execution is reconciled. Exceptions are tracked.
  5. Week 8: Report. The technical evidence pack is delivered: hash chain validation report, SoD verification record, three-way reconciliation pass rate, bi-temporal export, audit log schema, exit path documentation. Your security team signs off before any production expansion.