If you are the person who owns the platform inside the perimeter and the controls that the auditor attests to, this page is the technical evaluation. Syntheka runs self-hosted. The keys stay yours. The audit trail is append-only and hash-chained. The integrations are MCP-native. Honest on what we have and what we do not yet have.
Syntheka is built for that question. This page is the evaluation checklist we use with IT and Security leadership. Honest on what we do, what we don't do, and where we are not yet ready for your environment.
An IT and Security leader evaluating AI agent platforms is not asking about feature checklists. The question is where credentials live, where data lives, what the audit trail looks like, and whether the platform can be deployed under the controls you already attest to — SOC 2, ISO 27001, the internal control framework, the regulated environment.
Syntheka runs in three deployment topologies and integrates with the systems you already have. The integration surface is MCP-native; you can write your own integrations if you need to. The platform runs without any external network access if you need it to.
One-command bootstrap in your data center or private cloud. Data stays in your network.
Your team owns upgrades. The platform runs as a Docker Compose stack with the standard observability surface (OpenTelemetry, Prometheus, Loki, Grafana).
Runs in your AWS, GCP, or Azure tenant, in the region you choose.
Equivalent data sovereignty with the cloud provider's controls layered in. IAM, KMS, audit logs, and key custody stay with your team.
Runs without any external network access, including for LLM inference.
Model inference happens locally or via a private inference server. Audit trails are local. Updates are tarball-based. No egress required to operate.
MCP-native integrations for SAP, Salesforce, NetSuite, Procore, and the systems you already have.
SAP via OData / IDoc / BAPI / Events / CDC; Salesforce, HubSpot, Zoho; Oracle, Microsoft Dynamics 365, Sage, Foundation, QuickBooks Online.
OIDC, SAML, LDAP, Active Directory. Short-lived tokens; mTLS between services.
Your identity provider remains the source of truth for users and roles. The platform enforces roles server-side; no client-side trust.
OpenTelemetry traces, Prometheus metrics, Loki logs, Grafana dashboards.
Audit trail export as structured JSON for your SIEM. Hash chain validation as a callable API endpoint. Upgrade events in the same audit log as agent actions.
If any of these are required for your evaluation, Syntheka is not the right vendor today. We will tell you, and refer you elsewhere if we can.
Use these against any vendor, including us. If a vendor cannot answer them clearly, treat that as the answer.
Syntheka's pricing is published, not quoted. There are no per-action variable surprises because there are no per-action variables in the price.
| Tier | Price | Fits |
|---|---|---|
| Starter | $500 / month | One team, one workflow, one site |
| Professional | $2,000 / month | Multi-workflow, multi-site, multi-approver |
| Enterprise | Quote (custom) | Self-hosted, air-gapped, regulated environment |
A fixed-fee pilot is $1,500 for one site, 60 days, up to two workflows. The pilot pricing is honored for the first three customers.
Enterprise tier includes the technical evidence pack: deployment topology review, integration security review, hash chain validation report, audit log export schema, and the exit path documentation.
Most IT and Security teams we work with run a 60-day pilot on one integration (SAP, Procore, or Salesforce), then expand based on measured results. The pilot ends with a technical evidence pack, not a swap.