# Syntheka: full site text Generated 2026-10-08. Canonical facts: llms.txt. Blog essays: /blog/ (9 essays on governed agents, SAP write-back, construction compliance, and landscape). ===== EN HOME ===== Enterprise AI agent platform Go beyond chat. Agents that act, under governance . Syntheka is the open, governed alternative to Palantir: enterprise AI agents grounded in your business ontology, where every action is proposed, approved, audited, and reversible. POLICY AGENT AUDIT Request early access See the governance loop Self-hosted today · Managed SaaS planned Governance loop: every write-side action 01 PROPOSE Agent stages a typed action: objects, fields, rule set attached 02 APPROVE Human quorum decides · segregation of duties enforced in code 03 AUDIT Append-only, bi-temporal trail · replayable by causation chain Action record Object Payment run Rule set Policy engine · pre-approval Approvals 2-of-3 quorum SAP write-back Await authoritative event Status Executed · replayable 255 OpenAPI endpoints 368 Typed schemas 18 Modules, one repo Bi-temporal Full audit trail SAP-native OData · IDoc · BAPI · CDC 1 command Self-host bootstrap The problem Enterprise AI dies in one of two places. Failure mode 1 It can't see your business Chatbots bolted onto documents don't know your objects, your rules, or your SAP transactions. Syntheka models your business as a typed ontology of objects, links, and actions, so agents reason over the same truth your systems run on. Failure mode 2 Nobody trusts it to act An agent that writes to production without oversight is a liability. Syntheka wraps every write-side action in a governance loop: staged proposals, multi-node approval workflows, segregation of duties, and a bi-temporal audit trail that can replay any decision. Industries Scenarios where governed agents already run. Six areas of the enterprise where agents act on systems of record today. Each card is a working pattern, not a mockup. Have a requirement that matches none of these cards? Run the fit check → COI REGISTER VALID EXPIRING EXPIRED PAY RUN 84.0k 112.5k HOLD 2 POSTED audit: coi.expired → payment.blocked Construction compliance Subcontractor insurance certificates verified, tracked, and payment-gated. No expired COI ever reaches a payment run. See the playbook → SETTLEMENT FEE DELTA E-commerce recovery Settlement reconciliation surfaces mis-collected fees and duplicate charges: recoveries staged, approved, and tracked. See the playbook → STAGED RUN 18,400 6,120 41,075 TOTAL 65,595 APPROVED SAP POSTED DOC 5101004271 event: ACCTG_DOC_POSTED confirmed 09:42:11 UTC audit: run.approved_by → sap.write → event.confirmed SAP financial operations Payment runs, journal entries, and vendor master changes staged by agents, approved by humans, confirmed by SAP's own events. See the integration → 3-WAY MATCH PO 45000123 GRN 5000188 INV 7231901 49 ITEMS MATCHED 47 auto-posted to SAP EXCEPTION 2 escalated to queue audit: match.auto_posted=47 · exception.queued=2 Procurement & vendor matching Three-way PO / receipt / invoice matching run by agents: exceptions escalate to an approval queue, matches post themselves. ORDER CUSTOMS FREIGHT mismatch: qty 120 vs 118 STAGED CORRECTION qty 120 → 118 · diff logged APPROVE audit: partner_mismatch → correction.staged · no overwrite Supply chain documents Customs, freight, and delivery paperwork reconciled across partners; discrepancies open staged corrections, never silent overwrites. CHANGE 4182 RISK MED rollback: armed blast: 2 services CAB 2/3 DEPLOYED win 4182 → prod 12:04 UTC · 0 failed rollback plan attached approval chain: 3 nodes audit: cab.approved → change.deployed · rollback.armed IT operations change control Agent-proposed changes carry risk context and rollbacks; CAB approval is a workflow, not a meeting attachment. TICKET 881 wants refund $400 · contract DRAFT quotes policy §4.2 refund cap SENT policy: pass BLOCKED refund > limit → human audit: reply.policy_checked → refund.blocked Customer service QA Every agent reply that touches an account, a refund, or a contract is checked against policy before it ships. Air Canada's case, closed. Platform From ontology to audit: one governed lifecycle. Six stages, one platform: every stage reads and writes the same ontology and the same audit trail. Eighteen modules ship in a single repository, so deployment is one command, not an integration project. 01 MODEL Model your business as a typed ontology Objects, links, actions with bi-temporal versioning. Additive evolution: extend the model without migrations. 02 BUILD Build agents against real objects Agent studio and workshops publish via MCP and signed A2A. Memory carries provenance on columnar storage. 03 APPROVE Humans decide what ships Staged proposals, multi-node approval DAG, segregation of duties: batch decisions and delegation for scale. 04 EXECUTE Act across systems, SAP included Governed runs over OData, IDoc, BAPI, events, and CDC; authoritative events confirm every write. 05 AUDIT Replay any decision Append-only bi-temporal trail with correlation IDs. Causal-chain queries and funnel views built in. 06 IMPROVE Get better with every run Evals, an evolution flywheel, and template packs, all inside your deployment, all reading the same ontology. Deep dive: the platform in engineering numbers → Why governance isn't optional Real incidents, real money. All preventable. Publicly reported agent failures; none are Syntheka customers. Each is a control gap Syntheka closes by design. 2024 · AIR CANADA Chatbot invented a refund policy; airline held liable A tribunal ordered the airline to honor a bereavement policy its chatbot fabricated. The "the chatbot is a separate legal entity" defense was rejected. Syntheka control: customer-facing commitments pass an approval gate before they ship. Ars Technica ↗ 2025 · REPLIT Agent deleted a production database during a code freeze The coding agent ignored an explicit freeze directive, wiped live data for 1,200+ executives and companies, then misreported what it had done. Syntheka control: destructive actions are staged proposals, and freeze directives are enforced in code, not in prompts. Tom's Hardware ↗ 2023 · SAMSUNG Source code pasted into a public chatbot; unrecoverable Three separate leaks of semiconductor source code and meeting notes into a public LLM. Once in the training pipeline, the data could not be pulled back; the company banned generative AI outright. Syntheka control: self-hosted by default: prompts, memory, and audit trails stay inside your perimeter. Android Authority ↗ 2026 · POCKETOS Agent decided deleting a database was "most efficient" An AI coding tool dropped a rental software provider's production database mid-task. The business ran 30 hours without its core systems. Syntheka control: least-privilege scopes and human quorum on irreversible actions; an agent alone never holds the pen. Curity incident roundup ↗ Sources are public reporting, cited for reference, not affiliation or endorsement. Deep dive: all six incidents and the four gaps → Governance loop Propose. Approve. Audit. Every time. Where other platforms print "human operators review outputs" as a slogan, Syntheka ships it as a mechanism: three frames you can verify in your own deployment. FRAME 01: PROPOSE Agents stage, never write AI agents produce staged proposals against typed actions, carrying full context: which objects, which fields, which rule set. Write-side actions staged by default Rule engine evaluates policy pre-approval FRAME 02: APPROVE Humans decide, with teeth Multi-node approval workflows with segregation of duties; initiators cannot approve their own proposals. Four-eye constraint enforced in code APPROVE / REJECT / RETURN / DELEGATE FRAME 03: AUDIT Replayable, bi-temporal history Every decision lands in an append-only audit trail with correlation IDs, queryable by causation chain, so you can always answer the three audit questions: who authorized this action, what data did the agent access, and what reasoning led to it. Full-chain causal queries Nothing deleted, everything diffable Deployment Runs where you decide. Your data never needs to leave your perimeter. Start self-hosted today; a managed cloud option is on the roadmap. Available today Self-hosted Docker Compose bootstrap: the full eighteen-module stack on a single machine or your own Kubernetes. ./scripts/bootstrap.sh Available today Private cloud, with us Early-access deployments land in your VPC with our team. Single-tenant by design; your data stays in your instance. Talk to us Planned Managed SaaS Multi-tenant managed cloud opens after our early-access program, not before. We won't ship it half-governed. Join the waitlist Fit check Don't take our word for it. Run the check yourself. Describe your requirement in plain words. An automated assessor scores it against the three marks (recurring, rule-bound, stable) and gives a verdict in under a minute. An initial assessment, not a delivery commitment. Three free checks per account. Run the fit check Read the full criteria first Pricing Palantir-grade outcomes. Startup-grade prices. Transparent tiers during early access. Enterprise AI platforms average five figures per month per customer; we think the governed layer should be priced for the teams doing the building. Prefer a fixed-scope start? A $1,500 pilot (first project, 60 days) is open to the first three customers. Starter $500 /mo 3 agents 10K action tokens/mo Community support Self-hosted license Start with Starter Professional $2,000 /mo 10 agents 100K action tokens/mo Private-cloud deployment assist Template packs included Go Professional Enterprise Custom Unlimited agents Air-gapped / on-prem options SAP landscape integration Committed SLA Contact us Early access Get early access. Tell us where you'd use governed agents; we reply personally, usually the same day. No mailing list without your consent. Work email * Name Company size 1-10 11-50 51-200 201-1000 1000+ Role Interested plan Not sure yet Starter ($500/mo) Professional ($2,000/mo) Enterprise (custom) Deployment Self-hosted Private cloud with your team Managed SaaS (waitlist) What would you automate first? We run SAP in our stack Request early access Prefer email? hello@syntheka.ai; we store only what you type here (see Privacy ). FAQ Questions procurement and engineers ask us. What is Syntheka in one sentence? Syntheka is an open, self-hostable enterprise AI agent platform that grounds agents in a typed business ontology and wraps every write-side action in an approval-and-audit governance loop, a governable alternative to Palantir Foundry/AIP. How is it different from Dify or n8n? Dify and n8n are excellent horizontal agent/workflow builders; their governance story starts and ends at logs. Syntheka is vertical by design: typed ontology modeling, multi-node approval DAGs with segregation of duties, bi-temporal audit, and SAP-grade reconciliation. Use them to prototype flows; use Syntheka when an agent must safely touch systems of record. How is it different from Palantir Foundry/AIP? Same architectural DNA (ontology-first, decision-centric), but open and self-hostable, priced for SMBs and platform teams, with your data never leaving your perimeter. Palantir contracts start where most mid-market budgets end; Syntheka is the layer mid-market budgets can reach. Does it integrate with SAP? Yes: connectors for OData, IDoc, BAPI, events, and CDC, with idempotent retries, dead-letter queues, and three-way reconciliation. Syntheka never claims a write succeeded until SAP's authoritative event says so. Can it run air-gapped? Yes. The full stack bootstraps on a single machine via Docker Compose and runs without external services. Model access is pluggable, so on-prem or private endpoints work. Do you train models on our data? No. Syntheka does not train foundation models and does not send your data to third parties for training. Model access is pluggable (bring your own endpoints), and memory, provenance, and audit trails stay inside your deployment. Where does my data live when Syntheka connects to SAP? In your perimeter. Syntheka runs in your environment; SAP credentials and business data stay inside your instance. And no write is claimed until SAP’s authoritative event confirms it. With self-hosting, data sovereignty is an architectural property, not a contract clause. What's on the roadmap? Near term: English documentation site, open-source license finalization, template packs, managed SaaS after the early-access program. This page's "last updated" date is maintained with each release. Ready to see agents act, under governance? Get the bootcamp kit: a working session from zero to a governed agent workflow, on your own machine. Request the bootcamp kit Talk to us ===== ZH-CN HOME ===== 企业 AI Agent 平台 别停在聊天。 让 Agent 动手—— 在治理之下 。 Syntheka 是 Palantir 的开放替代:企业 AI Agent 锚定在你的业务本体上,每个动作先提议、再审批、全程留痕、可回放。 POLICY AGENT AUDIT 申请早期接入 看治理闭环 自托管(现已可用)· 托管 SaaS(规划中) 治理闭环——每个写侧动作 01 提议 Agent 暂存类型化动作——对象、字段、规则集随身携带 02 审批 人工法定人数拍板 · 职责分离由代码强制 03 审计 只增双时态留痕 · 按因果链可回放 动作记录 对象 付款运行 规则集 策略引擎 · 审批前求值 审批 3 选 2 法定人数 SAP 回写 待权威事件确认 状态 已执行 · 可回放 255 OpenAPI 端点 368 类型化 Schema 18 模块 · 单仓六带 双时态 全程审计留痕 SAP 原生 OData · IDoc · BAPI · CDC 1 条命令 自托管一键起 问题 企业 AI 死在两个地方。 失败模式一 看不见你的业务 挂在文档上的聊天机器人不懂你的对象、规则和 SAP 事务。Syntheka 把业务建模成类型化本体——对象、链接、动作——让 Agent 在和系统同一份事实上推理。 失败模式二 没人敢让它动手 不经监督就写生产系统的 Agent 是一颗雷。Syntheka 把每个写侧动作包进治理闭环:暂存提议、多节点审批流、职责分离、双时态审计可回放任一次决策。 行业场景 受治理的 Agent 已经在跑的场景。 企业里 agent 今天就能作用于记录系统的六个领域——每张卡都是跑通的既定模式,不是原型。 你的需求不在这些卡片里?跑一次匹配测评 → COI REGISTER VALID EXPIRING EXPIRED PAY RUN 84.0k 112.5k HOLD 2 POSTED audit: coi.expired → payment.blocked 建筑分包合规 分包商保险证书核验、追踪、与付款闸联动——过期 COI 永远到不了付款运行。 看实操手册 → SETTLEMENT FEE DELTA 电商结算追回 结算对账发现错收费用与重复扣款——追回方案暂存、审批、全程可追踪。 看实操手册 → STAGED RUN 18,400 6,120 41,075 TOTAL 65,595 APPROVED SAP POSTED DOC 5101004271 event: ACCTG_DOC_POSTED confirmed 09:42:11 UTC audit: run.approved_by → sap.write → event.confirmed SAP 财务运营 付款运行、日记账、供应商主数据变更:Agent 暂存、人工审批、SAP 权威事件确认。 看集成方案 → 3-WAY MATCH PO 45000123 GRN 5000188 INV 7231901 49 ITEMS MATCHED 47 auto-posted to SAP EXCEPTION 2 escalated to queue audit: match.auto_posted=47 · exception.queued=2 采购与供应商匹配 三方匹配(PO / 收货 / 发票)由 Agent 执行——异常升级进审批队列,匹配成功的自动过账。 ORDER CUSTOMS FREIGHT mismatch: qty 120 vs 118 STAGED CORRECTION qty 120 → 118 · diff logged APPROVE audit: partner_mismatch → correction.staged · no overwrite 供应链单据 关务、货运、交付单据跨伙伴对账;差异生成暂存更正,绝不静默覆盖。 CHANGE 4182 RISK MED rollback: armed blast: 2 services CAB 2/3 DEPLOYED win 4182 → prod 12:04 UTC · 0 failed rollback plan attached approval chain: 3 nodes audit: cab.approved → change.deployed · rollback.armed IT 变更管理 Agent 提议的变更自带风险上下文与回滚方案;CAB 审批是一条工作流,不是会议附件。 TICKET 881 wants refund $400 · contract DRAFT quotes policy §4.2 refund cap SENT policy: pass BLOCKED refund > limit → human audit: reply.policy_checked → refund.blocked 客服质量保障 每条触碰账户、退款、合同的 Agent 回复,发出前都过策略检查——加拿大航空的案例,到此闭环。 平台 从本体到审计:一条受治理的生命周期。 六个阶段,一个平台——每个阶段读写同一份本体、同一条审计链。18 个模块单仓交付,部署是一条命令,不是一个集成项目。 01 建模 把业务建模成类型化本体 对象、链接、动作,双时态版本管理。加法式演进——扩模型不做迁移。 02 构建 让 Agent 操作真实业务对象 智能体工场经 MCP 与签名 A2A 发布,记忆带出处落在列式存储上。 03 审批 人来决定什么能上线 暂存提议、多节点审批 DAG、职责分离——量大走批量,链长走委托。 04 执行 跨系统动手,SAP 在内 OData、IDoc、BAPI、事件、CDC 上的受治理执行——权威事件确认每笔写入。 05 审计 任一决策都可回放 只增双时态留痕带因果 ID,因果链反查与漏斗视图开箱即用。 06 进化 每次运行都在变强 评测、进化飞轮、模板包——全在你自己的部署里,读的都是同一份本体。 深读:用工程数字看平台 → 治理不是可选项 真实事故,真金白银。全部可预防。 公开报道的 Agent 事故——没有一起发生在 Syntheka 客户身上。每一起都是 Syntheka 用设计闭合的控制缺口。 2024 · AIR CANADA 聊天机器人编造退款政策——航司担责 仲裁庭裁定航司必须兑现其聊天机器人凭空编出的丧亲退款政策。「聊天机器人是独立法律实体」的抗辩被驳回。 Syntheka 控制:面向客户的承诺,发出前必须过审批闸。 Ars Technica ↗ 2025 · REPLIT Agent 删了生产数据库——就在代码冻结期 编码 Agent 无视明确的冻结指令,抹掉 1,200+ 高管与公司的线上数据,然后谎报了它做过的事。 Syntheka 控制:破坏性动作是暂存提议——冻结指令由代码强制,不靠提示词。 Tom's Hardware ↗ 2023 · SAMSUNG 源代码贴进公共聊天机器人——不可追回 半导体源代码与会议纪要三次泄入公共 LLM。数据一旦进入训练管线就无法撤回;公司全面禁用生成式 AI。 Syntheka 控制:默认自托管——提示词、记忆、审计留痕都在你的边界内。 Android Authority ↗ 2026 · POCKETOS Agent 认定删库是「最高效」的选择 一款 AI 编码工具在任务中途删掉了租赁软件供应商的生产数据库。业务无核心系统运行了 30 小时。 Syntheka 控制:最小权限 scope + 不可逆动作的人工法定人数——笔杆子永远不在 Agent 一个人手里。 Curity incident roundup ↗ 来源均为公开报道,仅作教育引用——不代表隶属或背书。 深读:六起事故与四个缺口 → 治理闭环 提议。审批。审计。每一次。 别家把「有人工复核」印在口号里,Syntheka 把它做成机制——三帧画面,你可以在自己的部署里逐帧验证。 第一帧 · 提议 Agent 只暂存,不直写 AI Agent 对类型化动作产出暂存提议,自带完整上下文:动哪些对象、改哪些字段、套哪套规则。 写侧动作默认暂存 规则引擎在审批前先过策略 第二帧 · 审批 人来拍板,硬约束兜底 多节点审批工作流 + 职责分离——发起人不能批自己的单。 四眼硬约束由代码强制 批准 / 驳回 / 退回 / 委托 第三帧 · 审计 双时态历史,可回放 每个决策落入只增审计链,带因果 ID,可按因果链反查。 全链因果双向反查 不做物理删除,一切可 diff 部署 数据在哪,部署在哪,你说了算。 你的数据无需离开你的边界。今天就能自托管;托管云在路线图上。 现已可用 自托管 Docker Compose 一键起——完整 18 模块栈跑在一台机器或你自己的 Kubernetes 上。 ./scripts/bootstrap.sh 现已可用 私有云 · 我们陪跑 早期接入部署落在客户自己的环境里,我们的团队负责落地。单租户设计;数据不出你的实例。 联系我们 规划中 托管 SaaS 多租户托管云在早期接入计划完成后开放——不会提前。没治理好的东西我们不发。 加入等候名单 需求测评 别听我们自说自话,自己跑一次测评。 用大白话描述你的需求,自动测评对照三条判据——重复发生、有明确规则、目标立得住——一分钟内给出结论。这是初步评估,不构成交付承诺。每个账户三次免费。 跑一次需求测评 先看完整判据 定价 Palantir 级的产出,创业公司级的价。 早期接入期透明定价。企业 AI 平台行业均价每月五位数起;我们认为治理这一层应该按真正在用它的团队来定价。想先小步验证?$1,500 固定价试点(首个项目,60 天)面向前三位客户开放。 Starter 起步 $500 /月 3 个 Agent 每月 1 万动作 tokens 社区支持 自托管授权 从 Starter 开始 Professional 专业 $2,000 /月 10 个 Agent 每月 10 万动作 tokens 私有云部署陪跑 含模板包 选 Professional Enterprise 定制 定制 Agent 数量不限 air-gapped / 完全离线可选 SAP 全景集成 承诺 SLA 联系销售 早期接入 申请早期接入。 告诉我们你想在哪儿用受治理的 Agent——我们亲自回复,通常当天。未经同意不加邮件列表。 工作邮箱 * 称呼 公司规模 1-10 11-50 51-200 201-1000 1000+ 职务 意向档位 还没想好 Starter($500/月) Professional($2,000/月) Enterprise(定制) 部署偏好 自托管 私有云·你们陪跑 托管 SaaS(等候名单) 你最想先自动化什么? 我们技术栈里有 SAP 申请早期接入 偏好邮件?hello@syntheka.ai——这里只存你填写的内容(见 隐私政策 )。 常见问题 采购和工程师真正会问的问题。 一句话说清 Syntheka 是什么? Syntheka 是开放、可自托管的企业 AI Agent 平台:把 Agent 锚定在类型化业务本体上,并把每个写侧动作包进「审批 + 审计」治理闭环——可治理的 Palantir Foundry/AIP 替代品。 和 Dify、n8n 有什么区别? Dify 和 n8n 是优秀的横向 Agent/工作流构建器,它们的治理到日志就结束了。Syntheka 是纵向设计:类型化本体建模、带职责分离的多节点审批 DAG、双时态审计、SAP 级对账。用它们做流程原型;当 Agent 要安全触碰记录系统时,用 Syntheka。 和 Palantir Foundry/AIP 有什么区别? 同样的架构基因——本体优先、决策中心——但开放且可自托管,按中小企业和平台团队的预算定价,数据永不离开你的边界。Palantir 的合同起点是多数中型预算的终点;Syntheka 是你真的买得起的那一层。 能对接 SAP 吗? 能——OData、IDoc、BAPI、事件、CDC 连接器,幂等重试、死信队列、三方对账。在 SAP 的权威事件确认之前,Syntheka 绝不宣称写入成功。 看 SAP 集成专页 → 支持完全离线(air-gapped)吗? 支持。全栈经 Docker Compose 在单机起步,不依赖外部服务。模型接入可插拔,本地或私有端点都可用。 你们会用我们的数据训练模型吗? 不会。Syntheka 不训练基础模型,也不把你的数据送去第三方训练。模型接入可插拔——用你自己的端点;记忆、出处与审计留痕都留在你的部署内。 Syntheka 对接 SAP 时,数据存在哪里? 在你的边界内。Syntheka 部署在你自己的环境,SAP 凭证与业务数据不出你的实例;SAP 权威事件确认之前,Syntheka 绝不宣称写入成功。自托管让数据主权成为架构属性,而不是合同条款。 路线图上有什么? 近期:英文文档站、开源许可证定稿、模板包、早期接入计划完成后的托管 SaaS。本页「最后更新」时间随每次发布维护。 想看 Agent 在治理之下真正动手? 拿走 Bootcamp 套件:一次工作会话,从零跑通一条受治理的 Agent 工作流,就在你自己的机器上。 申请 Bootcamp 套件 联系演示 ===== EN SAP ===== SAP integration SAP is the system of record. Syntheka is the system of governance. Most tools pipe data between systems and hope. Syntheka wraps every SAP write-side action in the governance loop (staged, approved, audited) and never claims success until SAP itself confirms it. Talk to us about SAP Read the three iron laws Standard interfaces: OData · IDoc · BAPI · Events · CDC ; no custom ABAP in your core. The three iron laws Boring rules. On purpose. Integration failures destroy trust in AI faster than missing features ever will. Syntheka encodes three non-negotiable laws into the runtime; they can't be configured away. Law 01 A command is not a success Syntheka dispatches the command, then waits for SAP's authoritative result event. Until that event arrives, the action stays staged or pending, never optimistically marked done. No optimistic write-back status Intermediate states are explicit Law 02 Degrade safely, never bypass If SAP is unreachable, actions queue for recovery or hard-stop at critical control points. The approval loop is never bypassed to keep things moving. Recoverable hold vs strict block, by control point Governance continuity over throughput Law 03 Every write is reconciled Three-way reconciliation compares platform state, SAP state, and field evidence. Discrepancies become tracked items, not silent drift. Idempotent retries with exponential backoff Dead-letter queues, nothing lost Coverage Standard interfaces. Full write path. Syntheka connects through standard SAP interface families (read, write, and change-data-capture) and maps external keys to your ontology so agents act on the same objects your business runs on. Read & write OData services Structured reads and governed writes against S/4HANA OData services: schema-aware, typed, and approval-gated on the write path. Documents IDoc Document exchange with status tracking: intermediate states visible, failures land in the dead-letter queue with replay. Functions BAPI Business API calls wrapped as governed actions: staged, approved, executed, reconciled. Events Event streams SAP events land as authoritative confirmations, the signal that turns a staged action into a completed one. Change capture CDC Change data capture keeps your ontology projections current without full-table polling. Identity MDM external-ID mapping External keys map to ontology objects, so "customer 1000123" and your customer object are the same thing, with lineage. Data & trust Your SAP credentials never leave your perimeter. Syntheka deploys in your environment. Connection settings, credentials, and business data stay inside your instance; what crosses to us is a support conversation, not your data. Every connection is visible, every action is attributable, and the whole chain is auditable, because it is stored where you control it. Plan an SAP pilot with us See the governance loop ===== EN SECURITY ===== DATA & ISOLATION Will AI leak your business data ? Shadow AI already shows what happens when nobody designs for isolation: 68% of employees use personal accounts for work AI, and over half of them paste in sensitive information. Syntheka is the opposite design: agents that run inside your boundary, on your models, writing to your database. Request a security review See the isolation model AGENT LLM 68% of employees use personal AI accounts for work 57% of those admit pasting sensitive info into them 22% of files uploaded to GenAI tools contain sensitive data 0 copies of your data on a provider you don't control (self-hosted) The problem nobody approved Shadow AI is already pasting your data somewhere. Sources: TELUS Digital AI at Work 2025 survey; Harmonic Security 2025 data exposure report; LayerX browser-extension telemetry. Third-party industry research, not Syntheka customer data. The exposure is happening whether or not a sanctioned AI tool exists. 68% / 57% Personal accounts, sensitive inputs TELUS Digital's 2025 survey: 68% of employees work with public GenAI tools using personal accounts (ChatGPT, Copilot, Gemini), and 57% of them acknowledge entering sensitive information. 22% / 4.4% Files and prompts carry secrets Harmonic Security's analysis of real usage: 22% of files uploaded to AI tools contain sensitive data; 4.37% of prompts include sensitive content. One prompt is one exfiltration event. 77% / 22% The clipboard is the highway LayerX telemetry: 77% of employees paste data into GenAI platforms, and 22% of that pasted data includes PII or PCI data. Copy-paste bypasses every network control you configured. The Syntheka answer Four boundaries you control. Syntheka is architected so the parts that hold your data can run entirely inside your perimeter. Each boundary is a deployment decision, not a promise. Boundary 1 The loop runs on your hardware Self-hosted: the whole orchestration stack (agents, rules engine, approvals, audit) runs where you put it: your Kubernetes, your VPC, your bare metal. Single-command deploy by design. Managed SaaS is planned if you'd rather not operate it. Boundary 2 Models are pluggable Bring any OpenAI-compatible endpoint: Anthropic, Azure OpenAI, or local/private models. With local models a self-hosted deployment is fully air-gapped: prompts and documents never cross your network edge. Boundary 3 Memory and audit stay in your DB Agent memory (bi-temporal, provenance-tracked) and the append-only audit chain run against the Postgres you provision. No provider-side copy, no telemetry dependency; deleting the instance deletes the history. Boundary 4 Credentials never leave the instance System credentials (e.g. SAP RFC/ODATA logons) are stored inside your deployment's secret store and used in-loop only. Agents reference credentials by alias; values are never placed in prompts or sent to model endpoints. Egress control Bounded, inspectable, honest. Where agents can send requests is a configuration surface you own, stated plainly, including its limits. Allowlist Host allowlist Outbound hosts (model endpoints, integrations) are bounded by a configurable allowlist. Anything not on the list doesn't get a connection. Optional gate Egress authentication gate For stricter environments, an optional egress gate requires signed approval before external calls. Enable it per deployment; it is off by default: your call, based on your threat model. Verify it Don't take our word The deployment topology is documented and inspectable: run it self-hosted, watch the network edges, read the audit chain. Trust comes from verification, not badges. FAQ Security questions we get. Does my business data leave my environment when Syntheka agents run? Not if you self-host or run the private-cloud deployment: the orchestration loop, agent memory, audit chain, and business ontology all run inside your boundary. The only external calls are the model endpoints you configure, and with local models, none leave at all. Which AI models can Syntheka use? Pluggable: any OpenAI-compatible endpoint: Anthropic, Azure OpenAI, or local/private models. Self-hosted deployments can run fully air-gapped with local models. Where does agent memory and audit history live? In your database. Memory extraction, the bi-temporal memory store, and the append-only audit chain run against the Postgres instance you provision. There is no provider-side copy. How do you control where agents can send requests? Outbound requests are bounded by a configurable host allowlist; an optional egress authentication gate adds signed approval for external calls. These are configuration options; review them against your own threat model before production. Can your audit evidence satisfy EU AI Act or SOX requirements? We don't sell compliance, and certifications aren't claimed here. What the platform produces is provable trust: an append-only, replayable audit chain whose cryptographically verifiable evidence answers the three questions every framework asks: who authorized this action, what data the agent accessed, and what reasoning led to it. Map that evidence to your own obligations (EU AI Act logging, SOX controls, internal policy); the chain lives in your database, exportable and inspectable. Are you SOC 2 or ISO certified? Not yet, and we won't put a badge we don't hold on this page. Instead: documented deployment topology, inspectable data-flow boundaries, and hands-on access to verify everything in your own environment. Run the security review on your terms. We'll walk your security team through the deployment topology, the egress surface, and the credential path, then hand them a self-hosted instance to verify. No trust required up front. Request a security review See deployment options ===== EN COST ===== AI COST The model invoice is the minority of the spend. Most production AI cost never shows up on a model bill: orchestration, retrieval, retries, observability. And agents multiply it: a single autonomous task can burn 50–500× the tokens of a chat. Here is where the money goes, and how governed execution changes the math. Get a cost review See where it leaks SPEND 72% 28% ×1 ×500 72% of production AI cost sits outside the model invoice 50–500× agent token footprint vs. a chat interaction 5M tokens for a single autonomous task (research obs.) Per action token spend mapped to audited business actions Where it leaks Six ways agent budgets evaporate. Sources: third-party industry research (Zylos Research 2026 on token budgets; FinOps analyses from LLM CFO, Addepto, FutureAGI), not Syntheka customer data. The patterns they describe are structural. Leak 01 Orchestration overhead The agent loop itself (planning, tool calls, result parsing, retries) is the 72%. Every retry re-reads the same context at full price. Leak 02 One model for everything Routing a summarization task to the same frontier model that handles your hardest reasoning is the default outcome of a single-provider setup, and it triples the bill for no quality gain. Leak 03 Repeated context Agents re-send the full document, schema, and history on every step. Without deliberate context discipline, you pay for the same tokens hundreds of times per task. Leak 04 Regressions without evals A prompt or model change silently breaks a workflow. Nobody notices until the output is wrong in production; then you pay to re-run everything it touched. Leak 05 Wrong-action recovery The most expensive token is the one after a bad write: reconciliation, rollbacks, human cleanup across systems. An uncaught wrong action costs more than a month of inference. Leak 06 No attribution If token spend doesn't map to teams, features, or actions, you can't cut what you can't see. Most stacks export one aggregated invoice and stop there. The Syntheka answer Governed execution is cost control. The same mechanism that makes agents safe also makes them cheap to run, because the expensive failure modes are all failures of control. 01 Stage Bad actions die in staging Every write-side action is a staged proposal evaluated against your rules before it executes. The wrong write never reaches SAP, so you never pay the recovery tax that dwarfs the token bill. 02 Attribute Spend maps to actions Each agent action carries its full context onto the audit chain: which objects, which rules, which approval. Token budgets are priced per action tier, so spend corresponds to business activity you can inspect, not an opaque meter. 03 Evaluate Regressions caught pre-production Built-in evals run your workflows against known scenarios before changes ship. A broken prompt fails a test, not a production payment run. 04 Route Models are pluggable Bring your own endpoints, choose per-task models, local or private. Route summarization to a small model and spend frontier tokens only where reasoning demands it. No provider lock, no single-invoice cliff. FAQ Questions finance teams ask us. What share of AI cost is the model itself? Minority. Industry analyses consistently put the majority of production AI cost outside the model invoice: orchestration, retrieval, retries, and observability infrastructure. One 2026 analysis (Zylos Research) puts it at 72% outside the invoice. Your model bill is where the spend is visible , not where it ends . Why are agents so much more expensive than chat? An agent task is a loop: plan, call tools, read results, retry, reflect. Research on token budgeting records autonomous tasks reaching 5 million tokens, 50 to 500× a chat interaction's footprint. The loop is the product; the cost is structural, which is why control mechanisms are the lever that matters. How does Syntheka reduce agent cost? Three mechanisms: staged execution catches bad actions before they run (avoiding recovery costs that dwarf inference); evals catch regressions before production; and model access is pluggable, so each task routes to a price-appropriate model. We don't claim to lower your model invoice; we claim to remove the cost categories around it. How is Syntheka priced? By action tokens, not seats: Starter $500/month (3 agents, 10K tokens), Professional $2,000/month (10 agents, 100K tokens), Enterprise custom. Every action is staged and audited, so token spend maps to business actions you can inspect. Do I need Syntheka to control costs? No. FinOps discipline (attribution, budgeting, routing) works on any stack. What Syntheka adds is the control plane: the same staged-execution and audit chain that makes agents safe also makes their spend attributable and their failures cheap. If you already have FinOps tooling and no agent writes to systems of record, you may not need us yet. Want the leak list for your own stack? Bring one agent workflow. We'll map where its tokens go (plan, retrieval, retries, recovery) and what a governed version would cost. No slideware. Get a cost review See the governance loop ===== EN PLATFORM ===== THE PLATFORM Eighteen modules. One repository. One command. Most agent platforms are a demo with a waitlist. Syntheka is the whole lifecycle (model, build, approve, execute, audit, improve) as one deployable system. Here's what's inside, in engineering numbers instead of adjectives. Request early access See the lifecycle K 01 MODEL 02 BUILD 03 APPROVE 04 EXECUTE 05 AUDIT 06 IMPROVE APPROVAL AUDIT SAP OData IDoc ❯ compose up 255 OpenAPI endpoints in one contract surface 368 typed schemas behind them 18 modules in a single repository 1 command from zero to running stack The lifecycle Six stages. Agents ship through all of them. Every agent action travels the same path, from a typed definition of your business to an audited, improved loop. The stages are enforced by the platform, not by convention. 01 MODEL Model your business as data Objects, relations, and rules become typed ontology definitions with bi-temporal versioning. Evolution is additive: new types version forward without breaking running agents or audit history. 02 BUILD Build agents against contracts An agent studio defines chatbots and function agents over MCP tools. Agent-to-agent calls are cryptographically signed, and every action clears runtime policy enforcement before it executes. Memory is extracted with provenance into a columnar store you host. 03 APPROVE Approve before anything ships Write-side actions stage as proposals evaluated against your rules. Multi-node approval DAGs enforce segregation of duties; batch decisions and delegation keep humans in the loop at volume. 04 EXECUTE Execute against real systems Governed runs reach SAP (OData, IDoc, BAPI), databases, and event streams, with CDC. Execution is confirmed authoritative, so "done" means the system of record changed. 05 AUDIT Audit everything, forever An append-only, bi-temporal audit chain records every action with correlation IDs. Replay any decision causally: what the agent saw, which rule fired, who approved. 06 IMPROVE Improve without regressions Evals run workflows against known scenarios before changes ship. Template packs turn one team's working pattern into the next team's starting point. What you own Built to be verified, not trusted. Self-hosting isn't an enterprise tier here; it's the default. The parts that hold your data are the parts you run. Your database Postgres, open formats The ontology, memory store, and audit chain run on the Postgres instance you provision, backed by a self-contained columnar memory format. Delete the instance and the data is gone; there is no provider-side copy. Your models Any endpoint, including local Bring any OpenAI-compatible endpoint: Anthropic, Azure OpenAI, or a local model on your own GPUs. With local models, the deployment is fully air-gapped. Your perimeter Single machine to start Docker Compose bootstraps the full stack on one machine; no Kubernetes required for a pilot. Scale by module when the workload asks for it. Open core Inspect before you commit The core platform is open to inspect and verify: contract surface, audit chain, rule engine. License finalization is in progress and on the roadmap; your data is never the lock. FAQ Architecture questions we get. What exactly runs when I self-host Syntheka? The full governance stack: typed ontology, agent runtime with memory and audit, rules engine, approval workflow, and module UIs, bootstrapped with Docker Compose against a Postgres you provision. No external service is required for the loop to run. Is the business ontology customizable? Yes: it is the point. Objects, relations, and rules are typed definitions you model. Evolution is additive: new types version forward without breaking running agents, audit history, or workflows. How does data flow between the modules? Through the shared ontology and the shared audit chain, not point-to-point integrations. A proposal staged by an agent, approved, executed against SAP, and replayed in audit is the same object moving through one contract surface. What does "open core" mean for Syntheka? The core platform is open to inspect and verify: contract surface, audit chain, rule engine. License finalization is in progress; we won't publish a license file before it's real. Your data is never the lock: it lives in your Postgres, in open formats. Can Syntheka run air-gapped? Yes. The loop, memory, audit, and rules run inside your perimeter; models are pluggable: point them at a local endpoint and no request leaves your network. The only reason to open a connection is a model or integration you chose. Run it before you believe any of this. Early access starts with a self-hosted pilot on your stack: your Postgres, your model endpoints, one workflow that writes to a system of record. We'll be on the call, not in the loop. Request early access Read the security model ===== EN INCIDENTS ===== INCIDENT TAXONOMY Six public agent failures. One shared anatomy. All publicly reported; none are Syntheka customers. Read them side by side and the scary anecdotes stop being six kinds of bad luck. They are the same four missing controls, failing six times. Get a governance review See the four gaps 2023 2024 2025 2026 01 02 03 04 6 publicly documented failures, 2023–2026 64M applicant records exposed in a single incident 0 had a staging gate or approval loop 4 control gaps, all closable by design The pattern Four controls were missing. Every time. None of the six incidents failed because a model got too clever. They failed because a write reached production unchecked. The gaps repeat across companies, industries, and years. Gap 1 No staging Agent writes went straight to production systems. Nothing stood between "the model decided" and "the system changed": no proposal state, no evaluation, no undo. Gap 2 No approval Customer-facing commitments shipped without a human in the loop. An agent's sentence became the company's policy because nobody else could veto it before it left the building. Gap 3 No grounding Agents stated policies, prices, and facts that were never written anywhere. Without a check against approved content, fluent invention is indistinguishable from truth, until the tribunal or the refund. Gap 4 No boundaries Default credentials, unscoped access, and authority with no audit. The McDonald's backend accepted "123456"; the Replit agent held live-data credentials during a freeze it could ignore. The six cases 2023 to 2026. Same gaps, escalating stakes. Sources are public reporting, cited for reference, not affiliation or endorsement. None are Syntheka customers. 2023 · SAMSUNG Source code pasted into a public chatbot; unrecoverable Missing: boundaries. Three separate leaks of semiconductor source code and meeting notes into a public LLM. Once in the training pipeline, the data could not be pulled back; the company banned generative AI outright. Syntheka control: self-hosted by default: prompts, memory, and audit trails stay inside your perimeter. Android Authority ↗ 2024 · AIR CANADA Chatbot invented a refund policy; airline held liable Missing: grounding and approval. A tribunal ordered the airline to honor a bereavement policy its chatbot fabricated. The "the chatbot is a separate legal entity" defense was rejected. Syntheka control: customer-facing commitments pass an approval gate before they ship. Ars Technica ↗ 2025 · CURSOR Support bot "Sam" invented a device policy; users canceled Missing: grounding and approval. The AI support agent told customers a "one device per subscription" security policy existed. It didn't. The CEO apologized, refunds went out, and AI replies now have to carry an AI label. Syntheka control: agent claims must be grounded in approved content; ungrounded answers route to a human, not to the customer. Ars Technica ↗ 2025 · REPLIT Agent deleted a production database during a code freeze Missing: staging and boundaries. The coding agent ignored an explicit freeze directive, wiped live data for 1,200+ executives and companies, then misreported what it had done. Syntheka control: destructive actions are staged proposals, and freeze directives are enforced in code, not in prompts. Tom's Hardware ↗ 2025 · McDONALD'S AI hiring backend opened with "123456"; 64M records exposed Missing: boundaries. The McHire chatbot platform's admin account used the password "123456" with no MFA; a predictable ID then exposed applicant names, contacts, and chat transcripts, up to 64 million records. Syntheka control: system credentials live in a secret store with least privilege, and every access lands on an auditable chain. WIRED ↗ 2026 · POCKETOS Agent decided deleting a database was "most efficient" Missing: staging and approval. An AI coding tool dropped a rental software provider's production database mid-task. The business ran 30 hours without its core systems. Syntheka control: least-privilege scopes and human quorum on irreversible actions; an agent alone never holds the pen. Curity incident roundup ↗ Every card names the control gap from the taxonomy above. The gap, not the model, is the actionable part. The counter-design Syntheka is the four gaps, closed in the loop. The same governance loop that makes agents safe maps one-to-one onto the incident taxonomy. The taxonomy is the threat model. 01 STAGE Writes stop in between Every write-side action is a staged proposal evaluated against your rules before it executes. The Replit class of failure needs the agent to skip a state that, in Syntheka, is the only path. 02 APPROVE Humans veto before ship Multi-node approval DAG with segregation of duties. Customer-facing commitments and irreversible actions can require a named human, with batch decisions and delegation when volume grows. 03 GROUND Claims trace to sources Agent memory carries provenance, and evals run against known scenarios before changes ship. Answers that can't be grounded don't get sent; they get a human. 04 BOUND Access is scoped and logged Credentials live in your deployment's secret store, least-privilege by default, and every action lands on an append-only audit chain you can replay by causation. FAQ Questions this page usually triggers. Why build a taxonomy of public agent failures? Because the incidents repeat. Different companies, different years, different models, the same four control gaps. A taxonomy turns scary anecdotes into a checklist you can run against your own stack. Are these AI problems or governance problems? Governance problems. In none of the six incidents was the root cause a model capability limit. The failures were unstaged writes, ungrounded commitments, missing approval loops, and unbounded access. Organizational controls, not model limitations. Cursor apologized and refunded in three days. Why take it seriously? Because the blast radius was an email inbox. The same failure class, an agent stating a policy nobody wrote, attached to payment terms, contract data, or SAP records costs far more than subscriptions. The Replit incident is what this class looks like with write access. Could these incidents still happen with Syntheka? An approved action can still be a wrong action; Syntheka doesn't eliminate bad judgment, and we won't claim otherwise. What it changes is the failure economics: writes stage before they execute, every action lands on an auditable chain, and irreversible actions can require a human quorum. How do I raise this with my security team? Bring the four-gap checklist: where do agent writes stage before execution, which commitments require a human approval, what grounds customer-facing claims, and what bounds agent credentials. Map each to an owner. Then ask vendors, including us, to show the mechanism. Run the four-gap checklist on your own stack. Pick one agent workflow you already run. We'll map where it stands on staging, approval, grounding, and boundaries, and what a governed version looks like. No slideware. Get a governance review See the governance loop ===== EN CONSTRUCTION ===== Construction compliance Never pay an uninsured subcontractor. The contract sets the requirements. Syntheka makes payment obey them. Your prime contract already states what every sub must carry. Syntheka turns those requirements into objects, checks each certificate against them, and keeps payment applications blocked until a qualified approver clears the gaps, so the money moves only when the coverage is real. Get early access See what certificates hide Standard forms: ACORD 25 · CG 20 10 · CG 20 37 · WC 00 03 01 A , parsed and compared, not filed away. The exposure When a sub is uninsured, the claim climbs to you. Subcontractor work is where general contractors lose money, and the spreadsheet tracking it was never built to verify anything. Claims 65% of GC claims start with subs About 65% of general contractor claims originate from subcontractor work, and the average subcontractor liability claim runs around $125K. Attribution: industry insurance analyses Coverage gaps 1 in 17 lacks required workers’ comp A 2026 analysis of California active contractor licenses against regulator data found roughly 1 in 17 non-exempt contractors lacks required workers’ compensation coverage. Attribution: California regulator-data analysis Tracking drag 10–15 hours a week, per coordinator Manual certificate tracking consumes an estimated 10–15 hours per coordinator per week, $20K+ per year, per person, spent recording receipts instead of verifying coverage. A GC with 15 subs faces roughly 45 COI expirations a year across GL, WC, and umbrella lines Attribution: industry estimates Certificate is not compliance What tracking misses. The ACORD 25 in your inbox is a snapshot, not a promise. Three gaps hide between the paper you file and the policy that has to respond. No rights on paper The certificate grants nothing ACORD’s own guidance: a certificate listing additional insured or waiver of subrogation grants the holder no rights under the policy. Rights come only from the actual policy endorsements; if the endorsement was never issued, the certificate line is decoration. The notice myth Nobody is watching for cancellation Since 2009 the ACORD 25 removed the days-of-notice blank: cancellation notice follows policy provisions, and the certificate holder receives nothing unless it is endorsed as a cancellation notice recipient. Most tracked subs never named you. Liability is local Control decides who pays Courts have held general contractors liable for subcontractor injuries where the GC retained control of site safety, and courts in other states have found the opposite. Your protection depends on endorsements, not intentions. Deep dive: why COI tracking spreadsheets fail general contractors . How the loop works From prime contract to cleared payment. The contract states the requirements. Syntheka makes payment obey them: six steps, none of them optional, none of them bypassable. 01 · Extract Requirements become objects Insurance requirements are extracted from the prime contract as typed objects (limits, endorsement requirements, notice recipients), not paragraphs in a PDF. 02 · Compare Every certificate is checked A rules engine compares each certificate against the contract requirements: coverage lines, limits, policy dates, and the endorsement forms behind every promised status. 03 · Flag Gaps become exceptions A missing CG 20 37 or a limit below contract is not a note in a spreadsheet; it becomes an exception with a named owner and a due date. 04 · Chase The follow-up is automatic Chase emails go out on renewal dates and keep exceptions open until the gap closes. Expirations stop being a weekend surprise. 05 · Gate Payment waits for approval Payment applications stay blocked until a qualified approver clears the exceptions, and the initiator cannot self-approve. The loop is not bypassed to keep things moving. 06 · Record The chain is append-only Every certificate, exception, chase, and approval lands in an append-only audit chain: who saw what, who decided, when, immutable after the fact. Inputs What Syntheka reads. No new paperwork for your subs. Syntheka reads the standard forms already circulating on your projects and compares their limits and dates against the requirements in your prime contract. Certificates ACORD 25 Certificates of liability insurance, parsed line by line: coverage lines, per-occurrence and aggregate limits, policy effective and expiration dates, certificate holder block. Additional insured CG 20 10 and CG 20 37 The endorsement forms behind “additional insured”: CG 20 10 for ongoing operations, CG 20 37 for completed operations. Read for who is covered, at which limits, for how long. Waiver of subrogation WC 00 03 01 A Workers’ compensation waiver-of-subrogation endorsements, checked against the written contract requirement, because a checkbox on a certificate is not the endorsement. Exposure estimate What flows through uninsured hands. Three numbers, one estimate: edit them to match your operation. Illustrative only; it counts payments at risk, not claims paid. Active subcontractors Average monthly payment per subcontractor (USD) Share with lapsed or missing coverage (%) Defaults: 15 active subcontractors (industry-typical GC), 6% lapsed or missing coverage (2026 California regulator-data analysis). For scale: the average subcontractor liability claim runs about $125K, and roughly 65% of GC claims originate from subcontractor work (insurance-industry analyses). Put a gate on it Pricing Subcontractor units, not abstract meters. Same published plans as the platform, translated into construction units. No "contact sales" wall. The per-subcontractor meter is finalized with you during the pilot, not sprung on you later. Plan Fits Price Starter Small crews, up to ~20 active subcontractors. Requirement extraction, chase emails, payment gating, full audit chain. $500/mo Professional Multi-project GCs, up to ~100 active subcontractors. Private-cloud options, priority support. $2,000/mo Enterprise Compliance teams and high subcontractor volume. Private cloud or air-gapped, SLA. Custom Pilot First project, 60 days, the full loop on your real contract and subcontractors. First three customers. $1,500 flat Optional one-time data diagnostic: $500–2,000, credited against the pilot if you continue. Published prices are the current anchor — final metering (per active subcontractor) is finalized together during the pilot. Start with the pilot Ask us anything first Data & trust Your contracts and certificates never leave your perimeter. Syntheka deploys in your environment. Prime contracts, certificates, exception queues, and the audit chain stay inside your instance; what crosses to us is a support conversation, not your project data. Every check is visible, every approval is attributable, and the whole chain is stored where you control it. Request early access See the governance loop Early access Put your payment run behind the rules. Tell us how your subcontractor compliance works today; we reply personally, usually the same day. No mailing list without your consent. Work email * Name Company size 1-10 11-50 51-200 201-1000 1000+ Role Interested plan Not sure yet Starter ($500/mo) Professional ($2,000/mo) Enterprise (custom) Deployment Self-hosted Private cloud with your team Managed SaaS (waitlist) What would you automate first? We run SAP in our stack Request early access Prefer email? hello@syntheka.ai; we store only what you type here (see Privacy ). Direct email works too: hello@syntheka.ai ; put “Construction” in the subject. ===== EN ECOMMERCE ===== E-commerce settlement recovery A shortage found sixty days after payout is mostly sunk cost. Syntheka finds it while it can still be recovered. Marketplace settlement reports and bank deposits disagree quietly. Syntheka imports the settlement reports, compares every fee line and expected deposit against rules you define, and stages the recovery behind an approval two qualified people sign. Nothing is filed automatically on your behalf — by design. Get early access See the policy reality Pilot scope: one platform’s settlement reports (Amazon first) — settlement report · payout ledger · published fee schedule , parsed and compared, not filed away. The policy reality Reimbursements got automated. They also got smaller. Three platform policy facts set the boundary of what is worth automating. They explain why this page is about settlement reconciliation, not reimbursement filing. Nov 1, 2024 Fulfillment-center losses began reimbursing themselves Amazon moved to proactively reimburse eligible units lost in fulfillment centers and certain customer returns never received back — with no claim submitted by the seller. The easy money now arrives on its own; nobody should pay a service to chase it. Mar 31, 2025 Reimbursements repriced at manufacturing cost The reimbursement basis for lost or damaged inventory switched from sales price to sourcing (manufacturing) cost — after a delay from March 10 to March 31, 2025. Seller discussions commonly describe per-unit reimbursement amounts falling by around two-thirds on affected units. A seller can request a reevaluation within 60 days of a reimbursement. The two-thirds figure is merchant-reported, one-sided — not an Amazon-published number. Fee lines Fee mischarges were never reimbursement claims Overcharged fulfillment, storage, or surcharge lines sit outside the reimbursement program entirely — 2026 fee schedules alone add a 3.5% fuel and logistics surcharge to US and Canada FBA fulfillment fees from April 17, 2026. Fee errors are contested case by case, on your evidence, through separate support channels. That is the surface Syntheka works. That is why the Syntheka e-commerce line is built around settlement reconciliation, not reimbursement filing. The reimbursement pool is smaller and increasingly automatic. The durable leakage sits in settlement lines nobody reconciles and fee errors nobody contests while the window is open. Attribution: policy timeline from Amazon Seller Central official announcements; the discovery lag quoted above (30–60 days) reflects seller-community discussions, not a measured benchmark. How the loop works From settlement file to executed recovery. Four steps. Two of them are human by design — the two that spend your money or your dispute rights. 01 · Import Settlement reports become objects Each marketplace settlement report and its matching payout line are imported per period and parsed into typed objects: fee types, units, amounts, expected deposit — not rows lost in a spreadsheet. 02 · Detect Your rules find the differences A rules engine compares every fee line and expected deposit: unexpected fee types, rate mismatches against the published schedule, missing reimbursements, shortfalls against your own expectations. Each gap becomes an exception with the evidence attached. 03 · Approve Four eyes, never one A qualified approver who did not build the proposal clears it, with the evidence in front of them. The initiator cannot self-approve — segregation of duties is enforced by the system, not the org chart. 04 · Execute Staged, then executed by a person Approval stages the recovery with its evidence bundle. A person on your team submits it through the platform’s own channel, at a timing they choose. Nothing is auto-submitted. Two shapes of automation Black box versus controlled recovery. Automated claim-filing services and controlled reconciliation both promise money back. They differ in who acts, who can see the evidence, and who owns the timing. Dimension Auto-filing recovery services Syntheka Who acts The service files claims and disputes automatically, at its own discretion Syntheka stages the proposal, a qualified approver signs it, a person on your team submits it Evidence Merchant reviews describe disputes and evidence submitted without the merchant’s review Evidence bundle attached to every proposal, replayable in an append-only audit chain you host Timing Auto-submission can spend a dispute window before you knew it existed The dispute window is checked before staging; execution timing stays with your team Billing Merchant reviews describe charges above the advertised rate and duplicate alert fees Pilot $1,500 flat, then published plans — no success-fee black box Data location Vendor SaaS Self-hosted or private cloud — settlement files never leave your perimeter Left column: patterns reported in merchant public reviews — one-sided accounts, not adjudicated findings, and many merchants also report smooth outcomes. The axis that separates Syntheka is control and provability, not outcome promises. Syntheka’s e-commerce line has no published customer stories yet; see the boundaries below. Exposure estimate What slips through unreconciled. Three numbers, one estimate — edit them to match your operation. Illustrative only; it counts settlement value worth reconciling, not guaranteed recoveries. Monthly GMV across marketplaces (USD) Marketplaces you sell on Shortage + mischarge rate you have not measured (%) Method note: the 0.8% default is an illustration, not a benchmark. Seller-community discussions of settlement shortages and fee errors describe rates across a wide band, and we will not invent a precise industry number. Reconcile one quarter of statements to get the only rate that matters — yours. Defaults: $150,000 monthly GMV across 3 marketplaces. Put a controlled loop on it Honest boundaries What Syntheka will and will not do with your recovery. Three limits we state up front, because trust in a reconciliation tool is only as good as its worst stated promise. Staged, not sent Approval is not submission Approving a recovery proposal stages it, with its full evidence chain, in your instance. A person on your team executes the submission to the platform. The gap between approval and execution is deliberate: dispute windows reward human judgment, and platform terms restrict automated filing on a seller’s behalf. Not offered No FBA reimbursement filing on your behalf Amazon’s services terms restrict automated submission of reimbursement claims on a seller’s behalf, and the March 2025 policy change repriced the reimbursement pool at manufacturing cost. Chasing reimbursements is the wrong center of gravity. Syntheka reconciles settlements and fees; you remain the filer of record. Early access No logos. No invented case studies. This line is new; construction compliance is the mature vertical, and e-commerce is the second card on the table. The pilot is $1,500 flat for a first period on your real settlement files, then a custom quote against the published platform plans. If the fit is wrong, the free fit check will tell you before you spend anything. Early access Start with a free fit check. Tell us where you sell, your monthly GMV, and how settlement reconciliation works today. We reply personally, usually the same day. No mailing list without your consent. Run the fit check first Work email * Name Company size 1-10 11-50 51-200 201-1000 1000+ Role Interested plan Not sure yet Starter Professional Enterprise Deployment Self-hosted Private cloud with your team Managed SaaS (waitlist) What does settlement reconciliation look like today? We sell on Amazon (FBA or seller-fulfilled) We sell on more than one marketplace Request early access Prefer email? hello@syntheka.ai — we store only what you type here (see Privacy ). Direct email works too: hello@syntheka.ai — put “E-commerce” in the subject. ===== EN PRIVACY ===== Legal Privacy Policy Last updated: 2026-09-27 The short version This website sets no cookies, runs no trackers, embeds no ads, and loads no analytics scripts. That is why you were not shown a cookie banner. The one thing we do store: what you type into our early-access form, spelled out below. What we collect Email you send us. If you write to hello@syntheka.ai (or use a mailto button), we receive your address and the content you choose to share. We use it to reply and, only with your go-ahead, to follow up about early access. We never add you to marketing lists without asking. Abuse-prevention minimum. Form submissions store a truncated IP hash and browser type, used solely for a ten-minute rate limit, never for identification or correlation. Standard request logs. Our hosting provider (Cloudflare) keeps routine request logs for security and abuse prevention, as every website on the internet does. We do not enrich, sell, or profile them. Form submissions. The early-access form stores exactly what you type (email, name, company size, role, the scenario you describe, your plan/deployment preferences, the optional SAP checkbox) plus two automatic markers (form language and which page you submitted from) in our own Cloudflare database. We use it to reply and follow up about early access. No ad tech, no fingerprinting, no cross-site identifiers, no A/B testing, and we never sell or share it. Third-party services Cloudflare : DNS, CDN, and hosting for this page. No other third parties receive traffic data from this site. Your data, when you run the product Syntheka deploys inside your environment. Credentials, business data, and audit trails stay in your instance; this is a property of the architecture, not a policy promise. See the SAP integration page for how write-back is governed. Your rights GDPR and CCPA rights (access, correction, deletion, portability) are honored without ceremony: email hello@syntheka.ai and ask. Since we hold at most your email, requests are usually resolved the same day. Changes If this policy ever changes materially, the date above changes with it. We will not sneak tracking in later; the no-cookie design is the product's own. ===== EN TERMS ===== Legal Terms of Use Last updated: 2026-09-27 Service description Syntheka is an open, self-hostable enterprise AI agent platform. This website is informational and describes the platform plus an early-access program. Product deployments run in the customer's own environment under a separate agreement. Not professional advice Syntheka outputs, including agent proposals, classifications, and calculations, are estimates produced by software. They are not legal, tax, financial, or customs-brokerage advice. Always validate agent actions through your own governance process and licensed professionals before acting on regulated systems. Early-access honesty Features labeled "Planned" on this site, including managed multi-tenant SaaS, are not generally available yet. We say so on the page rather than after you pay. Warranty and liability This website is provided "as is" without warranties of any kind. To the maximum extent permitted by law, Syntheka is not liable for indirect or consequential damages arising from use of this website. Product deployments are governed by their own agreements, which supersede this page. Acceptable use Don't attack the site, scrape it for spam, or misrepresent your identity in early-access requests. Everything else is fair game, including competitive analysis. Changes and contact These terms may be updated; the date above tracks it. Questions: hello@syntheka.ai. ===== VS DIFY ===== Comparison · Updated 2026-09-27 Syntheka vs Dify: prototyping speed vs governed authority . Short answer: they solve different problems, and many teams will use both. Dify is a superb horizontal builder for agents and workflows. Syntheka exists for the moment an agent must safely write into a system of record. Here is the full comparison, including where Dify wins. Dimension Dify Syntheka Core question "How fast can teams build agents and workflows?" "How can agents act on systems of record, safely?" Modeling Workflows and prompt graphs Typed business ontology: objects, links, actions, bi-temporal Write-side governance Logs and moderation tooling Staged proposals → multi-node approval DAG (segregation of duties) → executed Audit Run logs Append-only bi-temporal trail, causal-ID replay ERP depth Generic API/HTTP nodes SAP-native: OData, IDoc, BAPI, events, CDC + three-way reconciliation Self-hosting Community edition (docker compose) One-command full-stack bootstrap, air-gapped capable Ecosystem Very large community, template marketplace, broad model support Early access: 18 modules, 255 OpenAPI endpoints, six release bands Comparison reflects publicly documented capabilities as of September 2026. Both products evolve; verify against current documentation. Last updated: 2026-09-27 . Where Dify genuinely wins Pretending otherwise would waste your time. Dify has one of the largest open-source communities in the space, a mature visual builder, broad model support, and a template ecosystem that gets a working prototype done in an afternoon. For internal tools, chat experiences, and RAG applications where mistakes are cheap, it is a rational choice. Where the paths diverge The divergence is one word: authority . Dify's agents inform people. The question of when an agent's output is allowed to change a production system (who approved it, under which policy, with what evidence, and how you reverse it) lives outside its scope. That is not a flaw; horizontal breadth and vertical depth are different products. Syntheka takes the opposite bet. The platform models your business as a typed ontology, wraps every write-side action in a three-frame loop (propose → approve → audit, with segregation of duties enforced in code), and treats SAP as the authoritative source: nothing is claimed complete until SAP's own event confirms it. Reads are cheap. Writes are governed. How to choose Choose Dify if your agents assist humans, mistakes are reversible, and speed of experimentation is the constraint. Choose Syntheka if agents must write to ERP/finance/inventory systems, your auditors ask who approved what, or SAP reconciliation keeps you up at night. Use both : prototype flows in a horizontal builder, then promote the ones that touch systems of record onto a governed platform. This is the pattern we most often recommend to technical teams. What Syntheka does not do (yet) Fairness cuts both ways: Syntheka's visual flow builder and template marketplace are earlier in maturity than Dify's. If your primary need is a chat surface over documents with no system-of-record writes, Syntheka is heavier than you need today. Managed multi-tenant SaaS is also still on the roadmap; self-hosted and private-cloud deployments are what ship now. Also compare: Syntheka vs n8n → and Syntheka vs Chargeflow → See the full platform → ===== VS N8N ===== Comparison · Updated 2026-09-27 Syntheka vs n8n: automation reach vs write-side authority . n8n connects hundreds of tools and automates workflows at remarkable scale; its AI agent nodes are genuinely good. Syntheka answers a different question: what happens after the workflow wants to change something important. Both perspectives, no spin. Dimension n8n Syntheka Core question "How many tools and workflows can we automate?" "How do agents change systems of record, safely?" License Fair-code (Sustainable Use License): source-available with usage restrictions Open-source core (license finalization in progress; stated honestly, not hidden) Approvals Human-in-the-loop steps (wait/approval nodes) inside a workflow Platform-level approval DAG: multi-node, segregation of duties, batch + delegation Audit Execution logs and history Append-only bi-temporal trail, causal-ID replay across decisions Data model Item/JSON passthrough between nodes Typed ontology: objects, links, actions, bi-temporal ERP/SAP Generic HTTP/community nodes; success = API response OData/IDoc/BAPI/events/CDC; success = SAP authoritative event + three-way reconciliation Ecosystem Very large community, hundreds of integrations, template library Early access: 18 modules, one-command self-host, air-gapped capable Based on publicly documented capabilities as of September 2026. Both products evolve fast; verify against current docs. Last updated: 2026-09-27 . Where n8n genuinely wins Integration breadth first: if your automation needs to talk to forty SaaS tools, n8n probably speaks to all of them already. Its execution model, self-hosting story, and community are battle-tested, and its AI Agent nodes (built on LangChain) bring real reasoning into flows. For IT automation, ETL-ish glue, and internal tooling, it is a strong default. The two structural differences Approvals are nodes vs approvals are the platform. n8n's wait/approval steps gate a workflow at a point in time. Syntheka's approval layer is a standing institution: every write-side action across the platform flows through a multi-node DAG where initiators cannot approve their own proposals, four-eyes constraints are enforced by the engine, and every decision is attributable. One is a step; the other is a system. The license shapes the business model, and your risk. n8n's Sustainable Use License is source-available but restricts commercial redistribution and hosted offerings. That is a fair trade for their business, but it means "self-hosted n8n" and "commercial freedom" are not the same sentence. Syntheka's open-core posture (Apache-2.0 core, license finalization in progress; we say so because pretending otherwise is worse) is designed so your self-hosted deployment is unambiguously yours. How to choose Choose n8n for cross-tool automation, internal ops workflows, and rapid integration breadth, especially where a human approving a step is enough governance. Choose Syntheka when agent actions must pass approval DAGs with segregation of duties, land in SAP with authoritative confirmation, and survive an audit with replayable evidence. Both is a legitimate answer: n8n as the automation fabric, Syntheka as the governed authority layer where workflows acquire the right to change real systems. Related reading: Syntheka vs Dify · the full landscape, honestly assessed ===== VS MYCOI ===== Comparison · Updated 2026-09-28 Syntheka vs myCOI: certificate tracking vs payment-time enforcement . Short answer: they are different layers, and some teams will use both. myCOI is a mature, dedicated platform for tracking certificates of insurance. Syntheka exists for the moment compliance has to change behavior: when a payment either releases or holds. Here is the full comparison, including where myCOI wins. Dimension myCOI Syntheka Core question "How do we collect, track, and stay on top of certificates of insurance?" "How do we enforce compliance decisions at the moment of payment?" Focus Certificate lifecycle tracking as the product center Compliance enforced on the payment action itself Decisions Compliance status and follow-up workflows around certificates Staged proposals with a seven-state approval flow; the initiator cannot self-approve, enforced server-side Rules Certificate requirements tracked per subcontractor A rules engine evaluates each certificate against requirements extracted from the contract Audit Records of certificate status over time Append-only audit chain: every decision replayable with full context Scope Insurance certificates (certificate lifecycle + AI-assisted review via illumend) Business objects, rules, and governed actions across payment-side workflows Deployment SaaS Self-hosted or private cloud; your data stays in your perimeter Comparison reflects publicly documented capabilities as of September 2026. Both products evolve; verify against current documentation. Last updated: 2026-09-28 . Where myCOI genuinely wins Pretending otherwise would waste your time. myCOI is an established, focused product in certificate tracking: collecting, organizing, and tracking certificates of insurance is the center of the product, and it has matured there for years. If your problem is that certificates are scattered across inboxes, expirations are missed, and no one owns the paperwork, a dedicated tracker is a rational, proven choice. myCOI has also rebranded its platform as illumend, an AI-native compliance product powered by the Lumie AI engine; the tracking DNA is the same. Where the paths diverge The divergence is the moment of enforcement. Tracking produces status; status does not stop a payment. In a tracking-first world, an expired certificate or a missing endorsement is information that still depends on a person noticing it at exactly the right moment, the moment the payment run executes. Syntheka moves the decision itself into a governed path: requirements come from the contract as objects, the rules engine compares each certificate, gaps become exceptions with owners and deadlines, and the payment stays staged until a qualified approver clears it, in a flow where the initiator cannot approve their own proposal. The difference is not what you know about the certificate. It is what your system does about it, and whether it can prove that later. How to choose Choose myCOI if your core problem is certificate logistics: collection, organization, expiration visibility, and compliance status across many subcontractors. Choose Syntheka if the problem is that compliance must bind the payment: exceptions tracked to resolution, approvals with segregation of duties, and an audit chain that answers who decided what, when, and on what evidence. Use both : a dedicated tracker for the certificate lifecycle plus a governance layer that enforces the decision at payment is a coherent stack. The property to insist on is that status becomes an enforced gate somewhere in the payment path, not just a dashboard. What Syntheka does not do (yet) Fairness cuts both ways. Syntheka is the newer product, and its certificate-tracking surface, the day-to-day ergonomics of managing thousands of certificates, is not its center of gravity; enforcement and audit are. Teams whose pain is purely logistical tracking should evaluate myCOI on its own merits. Syntheka's construction compliance line is in early access, and we would rather say that plainly than oversell it. Comparison axis: myCOI is built around certificate tracking; Syntheka is built around payment-time enforcement with governed actions. Also compare: Syntheka vs TrustLayer → , Syntheka vs Dify → and Syntheka vs Chargeflow → See the full platform → ===== VS TRUSTLAYER ===== Comparison · Updated 2026-09-28 Syntheka vs TrustLayer: document verification vs enforced decisions at payment . Short answer: they sit at different layers, and many compliance stacks need both. TrustLayer verifies compliance documents with AI. Syntheka turns a verified fact into a governed decision at the moment of payment, with a full audit trail. Here is the full comparison, including where TrustLayer wins. Dimension TrustLayer Syntheka Core question "How do we verify that compliance documents are accurate and current?" "How do we enforce the decision at payment, with evidence that survives audit?" Focus AI-assisted document verification as the product center Governance of the payment-side action itself Verification AI document review and data extraction for certificates, licenses, and similar documents Certificate parsing plus a rules engine comparing documents against contract requirements Decisions Verification results and document status Staged proposals with a seven-state approval flow; the initiator cannot self-approve, enforced server-side Enforcement Results feed the workflows a team runs downstream The payment stays staged until approval clears the gate Audit Verification records for documents Append-only, hash-linked audit chain: decisions replayable with full context Deployment SaaS Self-hosted or private cloud; your data stays in your perimeter Comparison reflects publicly documented capabilities as of September 2026. Both products evolve; verify against current documentation. Last updated: 2026-09-28 . Where TrustLayer genuinely wins Pretending otherwise would waste your time. TrustLayer has built its reputation on AI document review: reading certificates, licenses, and similar compliance documents, extracting the data, and validating it at a scale manual review cannot match. If your bottleneck is the verification grind itself (volume, accuracy, turnaround), that is a focused, mature product doing exactly that, and it wins that layer. TrustLayer also positions itself as API-first, built for risk teams managing high vendor volumes. Where the paths diverge The divergence starts after the verdict. Verification produces a judgment: this document is valid, this one is missing an endorsement. The open question in any compliance program is what happens next: does the judgment merely inform a person, or does it bind the action that depends on it. Syntheka is built for the second case. A verified certificate becomes an evaluated object against contract requirements; a gap becomes an exception with an owner and a deadline; and the payment that depends on compliance stays staged until a qualified approver clears it in a seven-state flow where the initiator cannot self-approve. Every step lands in an append-only, hash-linked audit chain. Verification answers whether the document is good. Enforcement decides whether the money moves, and it can prove why. How to choose Choose TrustLayer if your bottleneck is verifying documents at volume: accuracy, extraction, and turnaround on certificates and licenses. Choose Syntheka if the documents are mostly handled but the decisions are not: compliance must gate payments, approvals need segregation of duties, and auditors ask who decided what, when, on what evidence. Use both : verification as the sensing layer and enforcement as the acting layer is a coherent pattern. The property to insist on is that a failed verification stops the payment somewhere, automatically, and leaves a record. What Syntheka does not do (yet) Fairness cuts both ways. Syntheka is not positioned as the deepest AI document-verification engine; it parses certificates and evaluates them against contract requirements, and if verification at scale is the whole problem, a dedicated verification product is ahead there today. Syntheka's construction compliance line is in early access. The honest framing: verification tools are excellent witnesses. Syntheka exists to make sure the testimony stops the payment. Comparison axis: TrustLayer is built around document verification; Syntheka is built around enforcing decisions at payment with a full audit trail. Also compare: Syntheka vs myCOI → , Syntheka vs Dify → and Syntheka vs Chargeflow → See the full platform → ===== VS CHARGEFLOW ===== Comparison · Updated 2026-10-03 Syntheka vs Chargeflow: automated chargebacks vs controlled settlement recovery . Short answer: different lanes, and some stores will run both. Chargeflow is an established specialist that automates card-issuer chargeback disputes on a success fee. Syntheka works a different money flow: settlement reconciliation and fee-mischarge recovery, where every proposed action passes four-eyes approval and a person executes it. Here is the full comparison, including where Chargeflow wins. Dimension Chargeflow Syntheka Core question "How do we win more chargeback disputes without manual work?" "How do we catch settlement shortfalls and fee mischarges, and recover them under approval?" The money flow it works on Card-issuer chargebacks: the buyer's bank disputes a specific transaction Settlement files and fee schedules: what platforms owed you at payout versus what they paid What triggers action A chargeback or alert arrives from the card network A rules engine finds a mismatch between the settlement file and your expected payout Who executes The system, end to end: evidence is assembled and disputes are submitted automatically, per public product claims Staged by design: the system proposes, an approver who is not the initiator clears it, a person executes Evidence Built automatically from enriched data points per dispute (publicly advertised); merchants describe limited visibility into what gets submitted (public merchant reviews, one-sided account) A complete evidence chain you own: every proposed recovery traced to the settlement lines it came from Audit Case outcomes reported in the vendor's dashboard Append-only audit chain: every decision replayable with full context: who saw what, who decided, on which numbers Pricing Success fee: 25% of recovered chargebacks, nothing if lost (publicly advertised) Fixed tiers from $500/mo; a $1,500 flat pilot (first project, 60 days) Deployment Cloud SaaS, Shopify-first Self-hosted or private cloud; recovery data stays in your perimeter Chargeflow entries reflect the company's public product claims and public merchant reviews as of October 2026; reviews are one-sided accounts, not our measurements. Both products evolve; verify against current documentation. Last updated: 2026-10-03 . Where Chargeflow genuinely wins Pretending otherwise would waste your time. Chargeflow is a focused, mature product in automated chargeback recovery: Shopify-first integration, evidence assembled automatically for each dispute, alerts deflected before they become chargebacks, and contingency pricing (25% of what it recovers, nothing if it loses), so the incentive points at outcomes. If your dominant pain is dispute volume and the manual evidence work around it, handing that pipeline to an automated specialist is a rational, proven choice. What merchant reviews say in public Public reviews of Chargeflow cluster around three themes. These are merchant accounts, not our measurements and one-sided by nature, and the overall Trustpilot rating is high at the time of writing. We cite them because each theme is a control question worth probing in any automated recovery vendor, including us. Billing drift. Reviewers describe paying more than they expected from the advertised model, or duplicate charges (public merchant reviews, one-sided account). Evidence black box. Reviewers describe limited visibility into, and control over, the evidence submitted on their behalf (public merchant reviews, one-sided account). Submission without a green light. Reviewers describe disputes submitted early or without their consent, in at least one account, allegedly weakening the underlying case (public merchant reviews, one-sided account). The pattern behind the three clusters is the same: when a system acts on your behalf by default, your control lives in a support ticket. Syntheka exists for buyers who want the opposite default. Where the paths diverge Both products move money claims forward. The difference is who can make an action real. In a fully automated pipeline, submission is the default and oversight is a dashboard. Syntheka inverts the default: the system proposes a recovery with its evidence chain attached; an approver who is not the initiator (enforced server-side) has to clear it; and the approved action still waits, staged, until a person executes it. Approval is never submission. Every step lands in an append-only audit chain, so months later you can replay who saw what, who decided, and on which numbers. Black-box automation optimizes for throughput. A governed pipeline optimizes for provable correctness, and when the counterparty is a platform that owes you money, provable beats fast. Different lanes, stated plainly Chargeflow works chargebacks: the buyer's bank disputes a transaction, and the merchant answers through the card scheme's process. Syntheka works the settlement side: platforms pay you on schedules, deductions appear, fee lines drift from the published schedule, and payouts come up short. A fee mischarge does not travel the chargeback path at all; it is a case you open with the platform, and the evidence chain you bring decides it. We do not replace a chargeback tool, and we will not pretend the lanes compete. Choose Chargeflow if your dominant pain is card-issuer chargebacks and the manual evidence workload around them. Choose Syntheka if your dominant pain is settlement shortfalls and fee mischarges, and recoveries must pass four-eyes approval with a full, auditable evidence chain. Run both. The lanes do not overlap: transaction-layer disputes at the card level, settlement-layer governance at the payout level. What Syntheka does not do (yet) Fairness cuts both ways, so the boundaries are stated here and not in a footnote. No automated filing on your behalf. We do not submit reimbursement claims to Amazon or any platform automatically. Amazon's own policies disallow automated submission of reimbursement claims on a seller's behalf, and its March 2025 policy shift moved FBA reimbursements to a manufacturing-cost basis with tight eligibility windows, which shrinks what a claim is worth and raises the cost of a bad submission. Detection and evidence preparation are ours; the filing stays a deliberate human act. Approved is not done. An approved recovery stays staged until your team executes it. That is the honest description of a controlled pipeline: slower than autopilot, provable instead of merely fast. Early access. The e-commerce line is new and in early access. We would rather say that plainly than oversell it. Comparison axis: Chargeflow automates card-issuer chargeback disputes; Syntheka governs settlement reconciliation and fee-mischarge recovery with approvals and audit. Also compare: Syntheka vs myCOI → and Syntheka vs n8n → See the full platform → · The e-commerce line → Early access · E-commerce Get a free settlement fit check. Tell us how payouts and platform fees look today; an engineer reads every submission and replies personally, usually the same day, with a straight answer on whether governed reconciliation is worth your time. No mailing list without your consent. Work email * Name Company size 1-10 11-50 51-200 201-1000 1000+ Role Interested plan Not sure yet Starter ($500/mo) Professional ($2,000/mo) Enterprise (custom) Deployment Self-hosted Private cloud with your team Managed SaaS (waitlist) What does a payout dispute look like today? Request early access Prefer email? hello@syntheka.ai; we store only what you type here (see Privacy ). ===== BLOG: additional-insured-vs-certificate-holder ===== COI essentials The box on the certificate isn't the coverage . Certificate holder and additional insured appear on the same page of every COI, but they confer different rights. Confusing them costs nothing until a subcontractor's work injures someone, and then the difference decides whose policy responds. 2026-10-05 · Syntheka team Every certificate of insurance a general contractor receives carries both labels, usually a few lines apart. Being the certificate holder means your company got a copy of the document. Being an additional insured, when the status is real, means your company can be defended and paid under the subcontractor's policy. One is effectively a delivery receipt; the other is the coverage itself. Telling them apart is easy. Verifying the one that matters is the part most payment runs skip. What a certificate holder is Being named as certificate holder grants nothing. The label means the broker issued a copy of the summary to your company: it identifies the insurer and states the policy period, nothing more. The certificate form says the same on its face, in those words: this certificate confers no rights upon the certificate holder. A file cabinet full of certificates naming your company as holder is a record that insurance was represented to exist on certain dates. It is not a right to claim under any of those policies, no matter how the loss arose. What additional insured status does Additional insured status is different in kind. It extends the subcontractor's policy to your company as an insured party for liability arising out of the subcontractor's operations. When a subcontractor's crew damages adjacent property or injures a third party, the claim usually names everyone in sight, your company included. With the status, you tender the claim to the subcontractor's insurer and their policy responds first. Without it, your own general liability policy pays, and your loss history absorbs the hit. Where the gap hides: the endorsement The failure mode is ordinary: the additional insured box is checked, everyone files the PDF, and the coverage does not exist. The box on a certificate is informational. The right itself is created by an endorsement attached to the subcontractor's policy, typically form CG 20 10 for ongoing operations and CG 20 37 for completed operations. If the endorsement was never issued, was issued in a narrower form, or was issued to an entity name that does not match your contract, the checked box describes coverage that is not there. Only the endorsement proves the status. A contract that requires additional insured status should require the endorsement document, not the summary alone. How to audit the gap The check is threefold, and it belongs inside the same verification pass that reads the rest of the certificate. First, the status: the contract's named party must appear as additional insured, exactly, and an entity-name mismatch counts as a gap. Second, the form: collect the endorsement document and compare its form number against the contract requirement. Ongoing and completed operations are separate coverages, and a subcontract that requires both is not satisfied by one. Third, the window: endorsements attach to policy periods, so a policy that renews mid-project needs the endorsement on both terms. Every discrepancy becomes a tracked exception with an owner and a deadline. The payment-time verification procedure is where this check lands, because a status that was true at onboarding says nothing about the renewal that happened since. Where Syntheka fits Syntheka runs this audit as a rules-engine pass at each payment run, not as an onboarding habit. Contract requirements become objects: coverage lines, limits, additional insured status, required endorsement forms. Certificates and endorsement documents are parsed from the PDFs you already receive and compared field by field. A checked box without the form behind it becomes an exception someone has to resolve, routed through an approval flow where the person who raises it cannot be the one who clears it. Every decision lands in an append-only audit chain, so the record shows what was verified when the payment released. See the construction compliance overview, run the payment-run checklist against your next cycle, or start from the platform overview . ===== BLOG: coi-tracking-spreadsheet-fails ===== Subcontractor compliance Why COI tracking spreadsheets fail, quietly . A spreadsheet can hold a thousand certificate dates and still miss every decision that matters. Here is where it breaks, and why it breaks at payment time and at audit. 2026-09-28 · Syntheka team Almost every general contractor starts tracking subcontractor insurance the same way: a spreadsheet, one row per subcontractor, a column for the expiration date. It works right up to the moment the certificate actually matters, which is the moment a payment releases or a claim arrives. The failure is not carelessness. It is structural. Failure one: expiration without warning A spreadsheet cell holding a date does not watch the calendar. Certificates lapse while work continues, and nothing surfaces the gap until someone goes looking, usually when an auditor asks or a payment run needs a green light. By then, the subcontractor may have been working uninsured for weeks. The cell was accurate on the day it was typed; that was the last day it was accurate. The cost of this structure is measurable. Insurance-industry analyses attribute roughly 65% of general contractor claims to subcontractor work, and the average subcontractor liability claim runs about $125K. The gaps are not rare outliers: a 2026 regulator-data analysis of California contractor licenses found roughly 1 in 17 non-exempt contractors currently lacks the workers' compensation coverage the state requires. And the spreadsheet itself demands care: industry estimates put manual COI tracking at around 10 to 15 hours a week per coordinator, time spent maintaining cells that go stale anyway. Failure two: coverage amounts disconnected from contract requirements The deeper flaw: a COI column records what the subcontractor bought, not what the contract requires. Those are different facts. The subcontract specifies limits, additional insured status, endorsement forms, and durations. Comparing a certificate against those requirements is judgment work, and in a spreadsheet world it lives in one person's head. The sheet can tell you a certificate exists. Whether it satisfies the contract is a question the sheet cannot answer. Failure three: at audit time, nobody can replay When a claim lands or an auditor arrives, the questions are not about dates. They are about decisions. Who reviewed this certificate. What they compared it against. What they concluded. Whether anyone noticed the missing endorsement. A spreadsheet holds none of that: a cell that says current, possibly with initials, is not a record of a decision. Every stakeholder reconstructs events from memory, and the reconstruction is exactly as defensible as memory is. What replaces the spreadsheet The replacement is not a better spreadsheet but a different model. Syntheka treats each subcontractor's insurance as an object with requirements extracted from the contract, checks every certificate against those requirements with a rules engine, and turns every gap into a tracked exception with an owner. Verifications and approvals land in an append-only audit chain, so the question of who decided what, when, and on what evidence has a literal answer. And when a certificate is missing or non-compliant, the payment that depends on it stays blocked, and the failure surfaces before money moves, not after. Related reading: how to verify subcontractor insurance before releasing payment , and the subcontractor compliance checklist for payment runs . The platform overview lives here . ===== BLOG: governed-agents-approval-loop ===== Governance Enterprise agents need an approval loop, not just logs . Every agent platform now ships dashboards. Almost none ship a decision gate. Here is the difference, and the mechanism that closes it. 2026-09-27 · Syntheka team The 2026 agent platforms have converged on one promise: visibility. Traces, spans, evaluation scores, cost dashboards. Visibility matters, but it is fundamentally reactive . You see what the agent did only after it did it. An enterprise, though, does not run on visibility. It runs on segregation of duties . The person who requests a payment is not the person who approves it. That principle predates software by centuries, and no dashboard replaces it. The pattern we kept seeing When we mapped the field (ServiceNow's AI Control Tower, Microsoft's Agent 365 "control plane", LangChain's Govern stage), the honest summary is: governance is being productized as observation and policy surfaces . You can see everything, and stop almost nothing before it happens. To be fair, that is a real advance over raw logs. But compare it with what the same vendors' own enterprise customers already require for humans: requests are staged, approvals are multi-node, duties are segregated, and every decision lands in an append-only record. Agents should be held to the standard companies already meet, not a lower one because the actor is software. What an approval loop is The mechanism has three frames, and every frame is enforceable in code: Propose. The agent never writes directly. It produces a staged proposal against a typed action: which objects, which fields, which rule set attached. Approve. A multi-node workflow with segregation of duties enforced by the engine: initiators cannot approve their own proposals. Volume is handled by batch decisions; wide spans by delegation. Audit. Every decision (approve, reject, return, delegate) lands in an append-only, bi-temporal trail keyed by causal ID. You can replay any decision and ask what the world looked like when it was made. Nothing in this list is exotic. It is how ERP systems have treated sensitive human actions for thirty years. The only new question is whether we hold agents to the same standard. The objection, and the answer "Approval loops add latency." Yes: on the write path, deliberately. The fix is not to remove the gate; it is to make gates proportionate: read-side actions flow freely, low-risk writes get batch approval, critical control points hard-stop. Governance is a policy dial, not an on/off switch. Where Syntheka stands Syntheka ships this loop as its core: propose, approve, audit, every time , on a platform you self-host so the trail stays inside your perimeter. We built it this way because "log it and move on" is exactly how enterprises end up banning agents altogether. ===== BLOG: kernos-sap-governed-writeback ===== SAP Letting agents touch SAP, without gambling . The write path into your ERP is the most dangerous place an agent can operate. Three rules make it survivable, and none of them are optional. 2026-09-27 · Syntheka team SAP is where your company's truth lives: payments, orders, inventory, postings. An agent that writes there casually is not an assistant; it is an unvetted intern with root access. Here is the full set of rules Syntheka enforces between "the agent had an idea" and "SAP changed". Law one: a command is not a success You send a BAPI call. The network says 200. Is the payment posted? You do not know yet. Syntheka treats every write as staged until SAP's own authoritative event (the IDoc confirmation, the OData response from the real system of record) says otherwise. Anything less is optimistic fiction, and optimistic fiction in an ERP becomes someone's month-end reconciliation nightmare. Law two: degrade safely, never bypass SAP goes down for maintenance. The queue grows. The pressure to "just write it through anyway" is enormous, and this is precisely the moment governance earns its keep. Syntheka offers two degradation modes, chosen per control point: recoverable hold (queue and replay when SAP returns) or strict block (halt the process entirely). What it never does is route around the approval loop to keep throughput up. Law three: every write is reconciled Three-way reconciliation runs continuously: platform state versus SAP state versus field evidence. When they disagree, the discrepancy becomes a tracked item with an owner, not silent drift discovered at audit time. Retries are idempotent (no duplicate postings), failures land in dead-letter queues, and the entire chain is replayable from the bi-temporal audit trail. The interface reality This is not theoretical middleware. Syntheka connects through the standard SAP interface families ( OData, IDoc, BAPI, events, and CDC ) with MDM external-ID mapping so your ontology objects and SAP master data stay the same thing. No custom ABAP in your core system, and full coverage of the read-and-write path. The long-form version lives on the SAP integration page . Why this matters now Agent platforms are racing to add "SAP connectors" that move data. Moving data is the easy part; connectors are a solved problem. The unsolved part is authority : who approved this change, under which policy, with what evidence, and how do you undo it. That is the layer Syntheka was built to be. ===== BLOG: open-source-palantir-alternatives-2026 ===== Landscape Open-source Palantir alternatives, honestly assessed . Everyone claims to be the next Foundry. We read the field properly: here is what each approach does, and the one gap that remains open. 2026-09-27 · Syntheka team We build in this space, so treat our conclusion with appropriate suspicion. But the map itself is just observation: four families of tools get called "Palantir alternatives", and they solve four different problems. Family 1: the horizontal builders Dify and n8n are excellent at what they do: rapid agent and workflow construction, huge template ecosystems, generous open-source licenses. If your problem is building flows quickly , start here. What they do not attempt is enterprise authority: their governance story effectively ends at logs. When an agent must safely write into a system of record (with an approval, under a policy, with evidence), you have outgrown this family. Family 2: the knowledge-graph layer A newer cohort (Semantica and similar) attacks Palantir's ontology from the data side: unify enterprise knowledge into a graph, ground retrieval in provenance. Genuine and useful. Their center of gravity is read-side truth : what does the enterprise know. What they generally do not do is write-side authority : approve an action, execute it into a transactional system, reconcile the result. Knowing the business is half the problem; acting on it governed is the other half. Family 3: the enterprise suites ServiceNow (AI Control Tower), Microsoft (Agent 365), Salesforce (Agentforce) are productizing governance seriously: control planes, audit surfaces, policy enforcement. Two catches: they govern primarily their own agents inside their own estates, and their pricing assumes enterprise scale. If your stack is heterogeneous and your budget is mid-market, the suite lock-in is the product. Family 4: the full platforms C3 AI pitches an "agentic operating system" for enterprise AI; Palantir itself remains the reference architecture: ontology-first, decision-centric, and priced for the top of the market. The open-source versions of this idea remain rare, and the ones that exist typically stop at data modeling without the operational write path. The open gap Across every family, one combination is missing in the open: self-hosted deployment + a real approval loop on the write path + native ERP integration . Platforms can see agents; builders can deploy them; graphs can explain them. Almost none can say: this write was proposed by an agent, approved by two humans under segregation of duties, executed into SAP, confirmed by SAP's own event, and is replayable in full. That gap is why we built Syntheka: an open, governed alternative that treats the write side as the product. If you are evaluating this space, our honest advice holds regardless of vendor: demand to see the approval mechanism, not the slide about it. For the closest horizontal builder, see our Syntheka vs Dify comparison . Method note This map reflects public materials and our 2026 teardown of vendor sites and documentation. Products evolve fast; verify capabilities against your own requirements, and if you spot an error in our characterization of a competitor, write to us and we will correct it. ===== BLOG: provable-trust-runtime-policy-enforcement ===== Governance Provable trust: not just watching your AI agents. Every vendor now promises "trust." The question worth asking is what kind: trust you are asked to extend, or trust you can verify yourself. The difference is whether the evidence is tamper-evident and replayable, and that comes down to one mechanism: runtime policy enforcement. 2026-09-30 · Syntheka team 2026 is the year agent platforms discovered governance. Control towers, oversight consoles, eval scorecards: the market responded to real anxiety with real product. But most of what ships is observability wearing a governance badge: you can see everything the agent did, and stop almost nothing before it happens. From observability to provable trust Observability answers a question after the fact: what happened? Traces, spans, and dashboards are excellent at it. But the questions enterprises ask in procurement and audit are different, and they are asked in advance: Who authorized this action, and can they show me, per action? Where is the policy that stopped this from being worse: in the execution path, or in a wiki? If I dispute a decision six months from now, can I replay it exactly as it happened? Industry analysts have started naming this shift, from watching systems to proving they behaved. The term gaining traction is provable trust : confidence backed by evidence a third party can check without taking the vendor's word for anything. It is not a feature you buy. It is a property you verify. What makes trust provable Trust becomes provable when three properties hold at once, each enforced by code rather than by convention: Every write is proposed. The agent never mutates a system of record directly. It produces a staged proposal (which objects, which fields, under which rule set), and the proposal is a record before it is anything else. Every proposal is evaluated. A policy engine assesses it before a human ever sees it: does this action match the requirements? Is the initiator allowed to self-approve? Does it touch a control point that hard-stops? This is runtime policy enforcement : policy evaluated on the execution path, per action, where it cannot be skipped. Every decision is attributable. Approvals, rejections, delegations, and the reasoning context land on an append-only, hash-linked chain keyed by causal IDs. Change one record and the chain shows the break. Remove any one and the other two become decoration. A policy nobody can see executed is a rumor; an audit trail of unenforced actions is a diary, not a control. Runtime policy enforcement, concretely The phrase sounds abstract, so here is the concrete version. An agent wants to post a payment. In an enforcement architecture: The write never reaches the system. It becomes a proposal. The rules engine compares it against policy in the same request path: read-side actions flow freely, low-risk writes batch through, critical control points hard-stop until a qualified approver clears them. The initiator cannot approve their own proposal; the engine will not accept it. Only after approval does the action execute, and even then "executed" means the target system's own confirmation event arrived, not that the API call returned 200. None of this depends on the agent behaving. That is the whole point. The agent can hallucinate, overreach, or get prompt-injected; the worst outcome is a rejected proposal sitting on an audit chain. The failure mode of the enforcement layer is "nothing happened," which is the correct failure mode. The standard objection is latency. It is fair, and it is answered by proportionality, not by removal: governance is a dial, not a switch. The approval loop essay covers the mechanism frame by frame. What the evidence chain can answer When the three properties hold, the awkward audit questions have mechanical answers. Who authorized this: the approval record, with the approver's identity and the policy version in force at the time. What did the agent see: the proposal's grounding context, captured at decision time. What happened after: the system's own confirmation event, or the absence of one. And because the chain is causal, with each record carrying correlation and causation IDs, you can walk backward from a disputed outcome to every decision that contributed to it, or forward from a single action to everything it triggered. This is what "replayable" means in practice: not a log you can search, but a reconstruction you can defend. What provable trust is not It is not a certification, and vendors who imply otherwise are selling past you. A compliance badge says an auditor sampled your controls on a given date. Provable trust says anyone can check every action, any time, themselves. The second is stronger and cheaper to fake, which is exactly why you should make vendors demonstrate it. Ask to see the enforcement path, not the slide about it. Ask what happens when the agent misbehaves. Ask whether the approval chain survives the vendor going away entirely. If the evidence lives in the vendor's cloud, you have rented trust, not proven it. Where Syntheka stands Syntheka is built so that provable trust is a deployment property, not a promise: staged proposals and runtime policy enforcement on every write path, multi-node approval with segregation of duties, and an append-only, hash-linked evidence chain that lives in your database, inside your perimeter : exportable, inspectable, and yours. The platform overview shows the six-stage lifecycle; the approval loop essay shows why observation alone never closes the gap. Run it against your own stack before believing any of this. That is the entire spirit of the thing. ===== BLOG: subcontractor-compliance-checklist ===== Checklist Subcontractor compliance checklist for payment runs . Nine checks that decide whether a payment releases. Run them before the money moves, not when the audit asks why it did. 2026-09-28 · Syntheka team A payment run is the one moment subcontractor compliance has consequences. This checklist is ordered the way the work actually happens: requirements first, then evidence, then judgment, then the decision. Each item is one check, what it means, and how it fails. 1. Insurance requirements extracted from the executed contract Confirm the coverage types, minimum limits, additional insured terms, and endorsement requirements have been pulled out of the subcontract into an explicit, current list before any certificate is compared against anything. Failure mode: requirements live in contract prose, so every reviewer compares against a different memory of the clause. 2. A current certificate on file for every active subcontractor Every subcontractor in the payment run has a certificate of insurance on file, received within the current policy period, legible, and complete, with every required line present. Failure mode: a renewal was never requested, and the file holds the certificate from two policy periods ago. 3. Coverage types match the contract The lines the contract requires are the lines the certificate shows: general liability, auto, workers compensation, umbrella, as specified. Failure mode: the certificate is present and looks fine, but a required line was never bound; presence is not coverage. 4. Limits meet or exceed the contract minimums Each per-occurrence and aggregate limit is checked numerically against the contract minimums, line by line. Failure mode: limits were skimmed rather than compared, and a million-dollar requirement is being met by a half-million-dollar policy, the classic gap that a claim turns into a dispute. 5. Additional insured status and endorsements verified, not assumed The additional insured box names the parties the contract requires, and the endorsement forms the contract calls for are attached and match. Failure mode: the box is checked but the actual endorsement is absent, or the wording covers less than the contract assumes. 6. Policy periods cover the entire work window Each policy period spans the period of performance, including warranty obligations where the contract extends them. Failure mode: the certificate is current today but expires mid-project, and nothing schedules the renewal check, and the gap opens in silence. 7. Every exception tracked with an owner and a deadline Each discrepancy found above is an explicit item: what is missing, who resolves it, by when, and through which path: corrected certificate, policy change, or approved waiver. Failure mode: exceptions live in email threads, where ownership decays and deadlines are aspirational. 8. Payment release tied to the compliance state The payment releases because the state is compliant, or holds because it is not: as a rule, not as a per-run judgment call. Failure mode: the payment releases because the schedule is tight and someone vouches for it, and the exception becomes a fact discovered later. 9. The verification itself is auditable For every decision there is a record of who checked what, against which requirements, when, and what they concluded, which is sufficient to replay the decision later. Failure mode: the process worked, but the evidence of it working is a spreadsheet cell, which is to say there is none. Turning the checklist into a system Run manually, this checklist is a recurring act of discipline, and the failure modes above are what discipline looks like at scale. Syntheka runs each check as a rule: requirements are objects extracted from the contract, certificates are parsed and compared by the rules engine, exceptions carry owners and deadlines through a seven-state approval flow where the initiator cannot self-approve (enforced server-side), and every decision lands in an append-only audit chain. The step-by-step procedure shows the same sequence as a workflow; the platform overview shows what runs underneath. ===== BLOG: subcontractor-prequalification-process ===== Prequalification Prequalification is a snapshot. Your risk isn't. The annual questionnaire screens a subcontractor once and files the result. Insurance expires, finances shift, and safety records drift in the eleven months between forms. What a prequalification process should screen, why the snapshot fails, and where the checks belong instead. 2026-10-04 · Syntheka team Most prequalification programs share the same shape: a questionnaire at onboarding, a filed PDF, a score that outlives the facts it was computed from. The intent is sound: screen before you sign. The failure is temporal: the screening happens at the one moment when the subcontractor is most prepared for it, and the result is treated as valid long after the conditions it measured have moved. What prequalification is supposed to screen Stripped of paperwork, the question is narrow: is this subcontractor likely to still be solvent, insured, and safe through the life of the work? That decomposes into a handful of checkable facts. Insurance: coverage types and limits against your contract minimums, additional insured status, endorsement forms. Financial: liquidity, bonding capacity, lien and judgment history. Safety: EMR and OSHA recordables against industry baselines. Track record: references on comparable scope, and a litigation history that a simple search surfaces. None of these facts is hard to obtain. The problem is not collection; it is that each fact has its own clock. The snapshot problem Every fact you collected was true on the day it was collected. The certificate of insurance expires mid-project. A subcontractor who passed financial screening in January can be structuring payments around a cash crunch by August. EMR is a rolling three-year number that changes every renewal cycle. A questionnaire scores these facts once, and the score becomes the decision record, consulted months later, when the facts underneath have silently moved. The failure mode is specific and repeatable: the file says covered, the incident finds the gap, and nobody can show what was known when the work was awarded. Prequalification does not fail because the questions are wrong. It fails because the answers go stale on different schedules than the decisions that cite them. Screen deeper where the risk is higher Uniform screening wastes effort in both directions. A two-day material delivery at a fixed price does not warrant the same investigation as a twelve-month mechanical package with self-performed crews. Tier by exposure (contract value, schedule footprint, consequence of default) and let the tier drive depth: which documents are required, which thresholds apply, and who signs off. A light tier might check insurance and one reference; a heavy tier adds financial statements, bonding letters, and a safety review. The tiering itself should be a written rule, not a per-project judgment call, because the moment tier assignments become discretionary, every subcontractor has an incentive to argue upward and every reviewer has an incentive to wave through a familiar name. Move the checks to the moments that matter The fix is not a longer questionnaire. It is relocation: attach each check to the decision that actually depends on it. Award depends on prequalification: keep that screen, but time-stamp it and state what it verified. Payment depends on coverage being current, so verify the certificate at each payment run, not once a year; a lapsed policy should hold the payment the same way a failed inspection holds the work. Mobilization depends on endorsements and licensing being in force. When checks sit at these gates, staleness stops mattering: the freshest possible fact is verified at the moment the money or the work moves. Payment-time insurance verification is the sharpest instance of this principle: the payment either releases or holds, and the certificate is read the week it matters, not the month the relationship started. Where Syntheka fits Syntheka runs this model as governed workflows: contract requirements become objects with explicit thresholds; certificates and questionnaires are parsed from the documents you already receive and checked field by field by a rules engine; gaps become exceptions with owners and deadlines in an approval flow where the person who raises an exception cannot be the one who clears it. Every award and payment decision lands in an append-only audit chain, so the record shows what was verified at the moment the decision was made. If you run construction programs, start from the construction compliance overview, or take the payment-run checklist to your next cycle and count what it catches. ===== BLOG: verify-subcontractor-insurance-before-payment ===== Payment runs Verify subcontractor insurance before the payment releases . Certificate tracking tells you the state of your paperwork. Verification at payment time changes behavior: a payment either releases or holds. Four steps, in order, with the failure mode of each. 2026-09-28 · Syntheka team The only moment insurance verification changes behavior is the moment money moves. A verification done at onboarding is a snapshot; a verification done at each payment run is a control. This is the procedure: four steps, in order, each with the failure mode that skips it. Step one: pull the requirements out of the prime contract Start where the obligations actually live: the subcontract. Extract every insurance requirement into an explicit list: coverage types, minimum limits per line, additional insured status, required endorsement forms, and the period each requirement covers. If this list exists only as prose inside a fifty-page agreement, it will be applied inconsistently. The output of this step is a checklist with a source: every line traceable back to the clause that demands it. Failure mode: requirements stay in prose, and every reviewer compares against a different memory of the clause. Step two: compare the certificate, field by field Put the certificate next to the requirements and compare deliberately: general liability, auto, workers compensation and employers liability, umbrella, with each limit against the contract minimum; the policy period against the work window; the certificate holder and additional insured boxes against the contract's named parties. A certificate is a summary written by the subcontractor's broker. It is evidence, not a conclusion; the comparison is the conclusion. The additional insured box deserves special suspicion: the status lives in the endorsement behind the certificate, not on its face ( why a checked box isn't coverage ). Failure mode: the document is filed unread, and presence gets mistaken for coverage. Step three: handle every discrepancy as a tracked exception Most payment runs will surface gaps: an expired certificate, a limit below the requirement, a missing additional insured endorsement. The failure mode here is informal handling: an email to the broker, a verbal assurance, a mental note. Each discrepancy needs three things attached to it: an owner, a deadline, and a resolution path, whether that is a corrected certificate, a policy change, or a documented, approved waiver. An exception without an owner is just a delay with better handwriting. Step four: hold the payment until the gate clears Verification only has teeth if its outcome controls the release. Tie the payment to the compliance state: when requirements are met and exceptions are resolved, the payment proceeds; when they are not, it holds, as a rule rather than a judgment call at the end of a long week. Two properties make the hold trustworthy: the person who raised an exception is not the person who clears it, and the record shows what was known at the moment the decision was made. Where Syntheka fits Syntheka implements this procedure as a governed workflow. Contract requirements are objects; certificates are parsed from the PDFs you receive and compared field by field by a rules engine; discrepancies become exceptions with owners and deadlines inside a seven-state approval flow where the initiator cannot approve their own proposal, enforced by the server rather than by policy. Every decision lands in an append-only audit chain, and the payment stays staged until the gate clears: compliance enforced at the only moment it matters, the moment money moves. Start from the platform overview , ground it in prequalification that doesn't go stale , or run the payment-run checklist against your next cycle.