Skip to content
Trust

Built to be trusted with real work

SyftOS is a governed platform for digital workers. It is designed so useful automation stays observable, reversible and under human control — with a person approving anything that changes the outside world and a complete record behind every step.

Human approval by default

Anything that touches an external system or business record becomes a request that waits in the Approval Centre for a named person. High-risk actions can never auto-approve, and no one can approve their own proposed action.

A tamper-evident audit trail

Every run, approval and action is recorded on an append-only log, linked into a per-tenant SHA-256 hash chain. Records cannot be edited or deleted, and you can export a signed copy for your own evidence.

Tenant isolation

Each customer workspace is logically isolated by a tenant identifier enforced at the application layer. Cross-tenant access is denied and returned as not-found — one customer can never see another.

Controlled integrations

You choose which tools to connect and with what permissions. Digital workers read and propose within those scopes, and side-effecting actions wait for your approval unless you deliberately configure otherwise.

Cautious AI data handling

We do not use your workspace content to train our own models, and the AI providers process API data under terms that do not train theirs. Where a provider offers it, SyftOS can request zero data retention.

UK data residency

The core application, database, cache and file storage are hosted in the United Kingdom. Where data is processed abroad (for example by AI providers), transfers are covered by the UK Addendum to the EU Standard Contractual Clauses.

See the detail

The documents behind these commitments.

Want a closer look?

Book a 30-minute demo on your own tools, or ask for a security review — we will walk you through the Approval Centre, the audit trail and how your data is handled.

Book a demo