Legal
Security & Trust Statement
Last updated: 30 June 2026
This statement explains the security, governance and trust controls used by SyftOS to support customer due diligence. It is kept accurate as the product, infrastructure, providers and controls change. It is not a SOC 2 certificate, ISO certification, penetration test report or legal guarantee.
1. Who we are
SyftOS is operated by Techshift Digital Ltd, a company registered in England and Wales.
- Company number: 15218025
- Registered office: 1 The Briars, Waterberry Drive, Waterlooville, England, PO7 7YH
- Website: https://syftos.com
- Security contact: security@syftos.com (interim fallback: mathew@techshift.digital)
In this statement, “SyftOS”, “we”, “us” and “our” refer to Techshift Digital Ltd when operating the SyftOS product, application, website, documentation, integrations and related services.
2. Purpose of this statement
This document summarises the security, governance and trust approach used by SyftOS. It is intended to help customers, design partners and reviewers understand the controls that support safe use of digital workers, workflows, approvals and connected integrations.
It should be read alongside the SyftOS Terms of Service, Privacy Notice, Data Processing Agreement, Sub-processor List, AI Data Use Statement, Acceptable Use Policy, Cookie Policy, Support and Early Access Policy, and any written order form or customer agreement.
3. Security philosophy
SyftOS is built around the principle that useful automation should be governed, observable and reversible where possible. The product is designed to help organisations adopt AI-assisted digital workers without giving unchecked automation direct control over important business systems. In summary:
- human approval is available for actions that affect external systems or business records;
- read-only information gathering is separated from write actions;
- customer workspaces are isolated from one another;
- agent activity is logged and reviewable;
- permissions and integrations are controlled by authorised users;
- autonomy is configured and monitored rather than assumed by default;
- customers can understand where their data is processed and which third-party providers may be involved.
4. Security controls at a glance
| Area | What SyftOS does |
|---|---|
| Tenant isolation | Each customer workspace is logically isolated by a tenant identifier enforced at the application layer on every tenant-owned record; cross-tenant access is denied and returned as not-found. |
| Authentication | Accounts with role-based permissions (five roles). Two-factor authentication (TOTP) and passkeys are supported and are mandatory for owner and administrator roles; a workspace can require 2FA for all members. SSO via SAML 2.0 and OIDC, and SCIM provisioning, are available. |
| Approval governance | Side-effecting and higher-impact actions are routed through human approval unless the customer has explicitly configured permitted automation; high-risk actions cannot be auto-approved, and the proposer of an action cannot approve it. |
| Audit logging | An append-only, tamper-evident audit log: each entry is linked into a per-tenant SHA-256 hash chain, with a signed export available. Records cannot be edited or deleted. |
| Encryption | Public connections served over TLS; integration secrets encrypted at rest with authenticated (AES-256) encryption; database and object storage protected by infrastructure-provider encryption at rest (see section 5). |
| Secrets handling | Credentials are decrypted only at the point of use through a single, audited path; they are never written to logs, queued jobs, API responses or AI prompts. |
| AI processing | Prompts and context are processed by Anthropic and OpenAI under their standard API terms (no training on API data); zero data retention is configurable where a provider offers it. |
| Data residency | The core application, database, cache and file storage are hosted in the UK (London); some providers process data in the US under appropriate transfer safeguards (see section 8). |
| Monitoring | Operational and security monitoring detects errors, incidents and degraded service; availability and incident updates are communicated to affected customers, with a public status page being established. |
| Outbound request safety | Connections to customer-configured endpoints and identity providers are screened to prevent server-side request forgery (SSRF). |
5. Encryption and secrets
Connections to and from the SyftOS application over public networks are served over TLS (HTTPS), provided by our hosting platform.
Integration credentials, API keys and tokens are encrypted at rest using authenticated (AES-256) encryption and are accessed only through a single, audited code path; they are decrypted only at the point of use and are never written to logs, queued jobs, API responses or AI prompts.
Customer data held in our managed database and object storage is protected by encryption at rest provided by our infrastructure providers.
6. Authentication and access control
Users access SyftOS through accounts, roles and workspace membership. Role-based access control assigns one of five roles per workspace, enforced through policy checks across the application, API, background jobs and realtime channels.
Two-factor authentication (TOTP) and passkeys are supported. Two-factor authentication is mandatory for users holding owner or administrator roles, and a workspace can require it for all of its members. Passwords must meet a minimum strength policy and are checked against known breached-password datasets. Single sign-on (SAML 2.0 and OIDC) and SCIM user provisioning are available for organisations that use an identity provider.
7. Human approval and governed actions
A key SyftOS control is the distinction between analysis and action. Digital workers may analyse information, generate summaries, draft content, recommend next steps or prepare proposed actions. Actions that affect external systems, records, customers, staff, money, code or other operational assets are subject to human approval unless expressly configured otherwise by the customer within permitted controls. High-risk actions cannot be auto-approved.
Customers remain responsible for reviewing outputs, approving or rejecting proposed actions, setting appropriate permissions and deciding how SyftOS should be used within their organisation. SyftOS should not be used as the sole decision-maker for legal, medical, financial, employment, regulatory, safety-critical or other high-risk decisions without appropriate human oversight and a separate written agreement.
8. Data residency and international transfers
The core SyftOS application, managed database, cache and object storage are hosted in the United Kingdom (London).
Some providers necessarily process data outside the UK — in particular the AI model providers, application monitoring and the marketing-site CDN, primarily in the United States. Where personal data is transferred internationally, those transfers are made under appropriate safeguards (such as the UK Addendum to the EU Standard Contractual Clauses) as set out in the Data Processing Agreement. The Sub-processor List sets out each provider’s processing location and transfer safeguard.
9. Customer workspace data
SyftOS may process customer workspace data to provide the service, including user account information, uploaded documents, connected integration data, prompts, agent instructions, workflow inputs and outputs, approvals, action proposals, run logs, audit records and support information.
Techshift Digital Ltd acts as processor for customer workspace content processed on behalf of a customer, and as controller for its own website, billing, account, sales, support and product communications data. This is explained further in the SyftOS Privacy Notice and Data Processing Agreement.
10. AI providers and model use
SyftOS uses third-party AI model providers — Anthropic (default) and OpenAI — to process customer prompts, instructions, documents, workflow context, connected system data and generated outputs where necessary to provide the service.
Customer workspace content is not used by Techshift Digital Ltd to train Techshift-owned models, and the AI providers process API data under their standard terms, which do not use that data to train their models. Customers should review the AI Data Use Statement and Sub-processor List for more detail.
11. Integrations and connected systems
Customers may connect SyftOS to third-party systems such as communication tools, project management tools, CRMs, finance platforms, storage providers, development platforms and other business systems. The exact integrations available may change over time.
Customers are responsible for ensuring they have authority to connect their systems, grant permissions, process data through SyftOS and allow digital workers to access or act on information from connected systems. Where an integration provider has its own terms, privacy rules, API limits or security requirements, customers and SyftOS users must comply with those requirements.
12. Personnel and organisational security
Access to customer data by Techshift Digital Ltd personnel is limited to what is reasonably necessary for support, security, maintenance, troubleshooting, onboarding, compliance or providing the service, on a least-privilege basis. Personnel with access to customer data are subject to confidentiality obligations.
13. Availability, monitoring and status
During early access, we communicate outages, degraded service, planned maintenance and incident updates directly to affected customers, and we are establishing a public status page at status.syftos.com.
During early access, SyftOS does not provide a guaranteed enterprise uptime SLA unless this is agreed separately in writing. We aim to operate the service responsibly, communicate material issues and improve reliability as the platform matures.
14. Incident response
If Techshift Digital Ltd becomes aware of a confirmed or suspected security incident affecting SyftOS, we will assess the issue, take reasonable containment and remediation steps, and notify affected customers without undue delay where required by law, contract or applicable policy.
Where we act as processor, we will notify the affected customer (as controller) without undue delay so that the customer can meet its own obligations, including the controller’s duty to notify the Information Commissioner’s Office within 72 hours where applicable. Breach handling is addressed further in the Data Processing Agreement.
Customers should promptly report suspected security issues, unauthorised account access, leaked credentials, suspicious workflow activity, unexpected integration behaviour or suspected data exposure to security@syftos.com (interim fallback: mathew@techshift.digital).
15. Data retention and deletion
SyftOS retains customer data only for as long as reasonably necessary to provide the service, comply with legal obligations, maintain auditability, resolve disputes, enforce agreements, support security, and operate backups and logs.
Customers may request deletion or return of customer workspace data in accordance with the Terms of Service and Data Processing Agreement. On termination, customer workspace data is deleted within 30 days, subject to limited legal, audit and backup retention as described in the Data Processing Agreement. Backup copies cycle out within a further limited period.
16. Code governance boundaries
Where SyftOS Code Governance features are used, SyftOS may help review, attest, route or govern proposed code changes and development workflow activity. SyftOS does not execute customer code, guarantee code quality or replace human engineering review unless expressly agreed in writing and technically implemented.
Customers remain responsible for their repositories, development environments, deployment processes, testing, review practices and production release decisions.
17. Customer responsibilities
Security is shared between SyftOS and the customer. Customers are responsible for:
- choosing appropriate users, roles and permissions;
- reviewing outputs and approving or rejecting proposed actions carefully;
- using strong account security and protecting login credentials;
- connecting only systems they are authorised to connect;
- configuring integrations and automation responsibly;
- ensuring customer data is lawful, appropriate and necessary for the intended use;
- not uploading or processing high-risk or sensitive data unless they have authority and appropriate safeguards;
- monitoring usage, costs, workflow behaviour and downstream effects;
- not using SyftOS to bypass human review, commit unlawful acts or abuse third-party systems.
18. Claims we do not make
Unless expressly confirmed in writing, SyftOS does not currently claim to be:
- SOC 2 certified;
- ISO 27001 certified;
- a regulated financial, legal, medical or employment decision system;
- a replacement for human review or professional judgement;
- a guarantee of error-free AI output;
- a guarantee of uninterrupted service;
- a guarantee that third-party integrations or AI providers will always be available;
- a system that can safely automate all business actions without customer configuration and oversight.
SyftOS may maintain SOC 2 readiness mapping, security evidence, internal policies and control documentation, but this is not a completed certification unless a formal audit and report have been obtained.
19. Security review and improvements
Security, governance and reliability controls will continue to mature as SyftOS moves from early access into wider commercial availability. Techshift Digital Ltd may update this statement, related policies, technical controls and customer documentation as the product evolves.
20. Contact
Questions about this statement or SyftOS security can be sent to:
- Security: security@syftos.com
- Privacy: privacy@syftos.com
- Support: support@syftos.com
- Legal: legal@syftos.com
During our early access period, mathew@techshift.digital is the interim fallback for any of the above.