Built so you can trust the work
Handing work to digital workers only makes sense if you stay in control. Governance isn't a layer we added — it's the reason SyftOS exists. Here is what that means in practice.
Human approval by default
Every action that touches the outside world becomes a request that waits in the Approval Centre for a named person. Agents can never approve their own work; that permission is reserved for people, always.
Tamper-evident audit trail
Every event is written to an append-only log that is hash-chained per tenant. Any edit, deletion or reorder breaks the chain and is provably detectable, and the trail exports with a signature for your auditor.
Strict tenant isolation
Automatic query filtering, ownership re-checks, per-tenant file prefixes and isolation tests that gate every release. Cross-tenant access is denied, not merely discouraged.
Encrypted secret vault
Integration credentials are encrypted and scoped per tenant, connected by OAuth or API key, never exposed to an agent and never written to logs, queues or model context.
Roles & two-factor auth
Five scoped roles (owner, admin, operator, approver and viewer) decide who configures, who approves and who only watches. TOTP two-factor authentication is available to every member and can be required for privileged roles or across the whole organisation.
Single sign-on & SCIM
One identity provider per tenant over SAML 2.0 or OIDC, with role mapping and SCIM directory-driven provisioning. Available from the Growth tier upward.
Governance over AI-authored code
Govern the pull requests your AI coding tools already produce on GitHub: a distinct-approver merge gate and an immutable attestation on the same trail. SyftOS governs the change — it never runs your code.
Provider & residency controls
Choose which AI providers an agent may use, request providers opt out of data retention, and control how long run history is kept. Governance over the model, not lock-in.
“No autonomous side effects. Every action that changes the outside world is proposed by an agent and approved by a person — and the whole story is in the audit log.”
It's a simple rule, enforced everywhere: agents reason and recommend; people stay accountable for what actually happens.
Yours, and only yours
Each organisation is a separate tenant with its own isolated data and credentials. Agents only see the tools you connect and the access you grant. Connecting one service never silently grants another.
SyftOS is built and operated by Techshift Digital Ltd, a UK company, under UK GDPR and the Data Protection Act 2018.
-
Scoped credentials
Integration tokens are encrypted, per-tenant, and never shared between organisations.
-
Least privilege
Agents are granted only the specific tools they need, nothing more.
-
Reproducible by version
Immutable published versions mean a result can be re-examined exactly as it ran.
-
Full traceability
From the trigger to the approval to the outcome, every step is recorded.
Control over every action
The differentiator isn't the model. It's the controls around it. These guarantees hold for every department, every agent and every run.
Human approval by default
Side-effecting tool calls become actions that wait in the Approval Centre. Agents propose; people decide. An agent can never approve its own work.
Tamper-evident audit trail
Every event is written to an append-only log that is hash-chained per tenant. Any edit, deletion or reorder is provably detectable, and the trail exports with a signature.
Earned autonomy, never assumed
Relax the gate one notch at a time for a proven agent and action, only on a measured trust score, always reversible, and snapped back on any failure. High-risk actions never auto-approve.
Tool guardrails
Constrain what each tool may do with allow-lists, payload caps and PII redaction, so an agent stays inside the lines you set, before approval is ever reached.
Per-agent budgets
Cap spend and usage per agent and per workflow. When a budget is reached, work stops — no runaway costs, no surprises on the invoice.
Provider & residency controls
Choose which AI providers an agent may use, opt them out of data retention, and control how long run history is kept. Governance over the model, not lock-in.
What enterprise asks for
Identity, isolation, secret handling, code governance and the evidence your auditor needs, all built into the platform and described exactly as they stand today.
Single sign-on & SCIM
One identity provider per tenant over SAML 2.0 or OIDC, with attribute and role mapping, plus SCIM directory-driven provisioning and de-provisioning. (Available from the Growth tier.)
Code Governance
Govern the pull requests your AI coding tools already produce: a distinct-approver merge gate and an immutable attestation binding the diff, the detected tool, the named approver and CI status. It governs the change — it never runs your code. (GitHub today.)
Multi-tenant isolation
Every tenant is strictly walled off by automatic query filtering, ownership re-checks, per-tenant file prefixes and isolation tests that gate every release. Cross-tenant access simply does not exist.
Encrypted secret vault
Integration credentials and tokens are held encrypted and scoped per tenant, connected by OAuth or API key, never exposed to an agent.
SOC 2 readiness evidence
An auditor-facing evidence pack maps the SOC 2 Trust Service Criteria onto controls already implemented in the platform. This is readiness tooling and evidence, not an issued SOC 2 certification.
Data Processing Agreement
UK GDPR-aligned processing, named sub-processors and a Data Processing Agreement on request, with provider and data-residency controls available on Enterprise terms.
Built for due diligence
Everything here is true today. Where a formal certification or examination is still ahead of us, we say so plainly — we would rather be straight with your security team than overclaim.
UK GDPR & DPA 2018
Built and operated by a UK company. We are the controller for account data and your processor for the content your agents work with, governed by a Data Processing Agreement we provide on request, setting out instructions, sub-processors and breach notification.
Named sub-processors
The sub-processors that touch data today: Anthropic (default model), OpenAI (optional model, embeddings and search), Stripe (billing), Laravel Cloud (hosting) and AWS S3 (object storage). The integrations you connect are generally your own sub-processors.
Data export & deletion
Need a full export? Ask us and we will assemble every record plus your document files. On closure your data is retained for a defined window (90 days by default), then deleted.
Card data never touches us
Billing runs through Stripe; card details are handled entirely by Stripe and never stored on the platform.
SOC 2 — readiness evidence, not certification
An auditor-facing evidence pack maps the five SOC 2 Trust Service Criteria onto controls already implemented: RBAC, hash-chained audit, encryption and isolation testing. Each one points to the table, command, event or test that proves it. This is readiness tooling and evidence, not an issued certification: SyftOS is not SOC 2 certified.
Responsible by design
High-risk actions can never auto-approve, enforced at publish time and again at runtime. The approved payload is the executed payload, verified by hash. Credentials never enter logs, queues, model context or responses.
Need our sub-processor list, a Data Processing Agreement or a security questionnaire completed? Ask us and we will turn it around.
Responsible disclosure
Found a security issue? We want to hear from you. Email us and we'll respond quickly.
Run the security review with us
Bring your questionnaire. We'll walk your team through how SyftOS handles isolation, approvals and auditability, then share our sub-processor list and SOC 2 readiness evidence pack, with a Data Processing Agreement on request.
SyftOS is in early access — creating a workspace starts a guided setup with a dry-run sandbox, not instant billing.