Syntheka does not certify compliance. Syntheka provides the technical foundation: bi-temporal audit trail, hash-chained records, segregation of duties, three-way reconciliation. Your conformity assessment body or your self-assessment works with this evidence.
Syntheka is not a notified body. Syntheka is not a conformity assessment body. Syntheka does not represent itself as certifying any customer's compliance status.
Each capability is observable in a Syntheka pilot within 60 days. None requires SOC 2 or ISO 27001 to begin; both certifications are in progress.
| EU AI Act article | Requirement (paraphrased) | Syntheka support |
|---|---|---|
| Article 9 Risk management system |
Continuous risk management across the lifecycle of a high-risk AI system. | Bi-temporal audit log + append-only hash chain. Every action records both transaction time and valid time. The chain flags any retroactive edit, including by an admin. |
| Article 10 Data and data governance |
Training, validation, and testing data sets must be relevant, representative, and free of errors. | Partial alignment: Syntheka governs the actions an AI agent takes, not the training data. For AI agents that operate on your data, the typed business ontology and the rule engine act as guardrails before the data is touched. |
| Article 11 Technical documentation |
Technical documentation must demonstrate conformity and provide information to notified bodies. | Syntheka exports the audit trail in structured JSON, suitable for inclusion in the technical documentation pack. The export includes causal-chain replay for any action. |
| Article 12 Record-keeping |
Automatic recording of events and logs over the lifecycle of the system. | The append-only audit log is the primary record-keeping artifact. Retention is set per the deployment; minimum recommended retention is seven years for financial systems of record. |
| Article 13 Transparency to deployers |
High-risk AI systems must be transparent to deployers, allowing them to interpret outputs and use appropriately. | Every action record includes: the actor (human or agent identity), the object (typed business object), the rule set evaluated, the approval trail (who approved when), the system of record confirmation (three-way reconciliation result), and the outcome (executed / blocked / reverted). |
| Article 14 Human oversight |
Effective human oversight during the period of use. | The approval DAG enforces segregation of duties server-side. The initiator cannot self-approve. A qualified human reviewer is required for every consequential action; the system refuses to record an approval from the same identity as the requester. |
If any of these are required for your decision, we will say so now, not after the contract is signed.
The same Syntheka deployment behaves differently under EU AI Act depending on whether you run it self-hosted, in your private cloud, or in a Syntheka-managed environment (which does not exist today for multi-tenant SaaS).
Syntheka runs in your infrastructure. You control the data, the keys, the network. The technical evidence for Article 9, 11, 12, 13, and 14 is entirely under your control. Recommended for high-risk systems.
Syntheka runs in your private cloud account (your AWS, your GCP, your Azure tenant). Equivalent evidence, with the cloud provider's controls layered in. Your data residency is in the region you choose.
Multi-tenant SaaS is not a Syntheka product. The economics and the AI Act compliance boundary would each be different, and we are not yet ready to offer this. We will revisit this when the underlying platform maturity and certifications are in place.
Most customers use the pilot to produce the technical evidence they then present to their notified body or to their internal audit.
Pilot pricing is $1,500 flat for the first three customers. We are honest about what the pilot proves and what it does not prove.