Built to be trusted with real work
SyftOS is a governed platform for digital workers. It is designed so useful automation stays observable, reversible and under human control — with a person approving anything that changes the outside world and a complete record behind every step.
Human approval by default
Anything that touches an external system or business record becomes a request that waits in the Approval Centre for a named person. High-risk actions can never auto-approve, and no one can approve their own proposed action.
A tamper-evident audit trail
Every run, approval and action is recorded on an append-only log, linked into a per-tenant SHA-256 hash chain. Records cannot be edited or deleted, and you can export a signed copy for your own evidence.
Tenant isolation
Each customer workspace is logically isolated by a tenant identifier enforced at the application layer. Cross-tenant access is denied and returned as not-found — one customer can never see another.
Controlled integrations
You choose which tools to connect and with what permissions. Digital workers read and propose within those scopes, and side-effecting actions wait for your approval unless you deliberately configure otherwise.
Cautious AI data handling
We do not use your workspace content to train our own models, and the AI providers process API data under terms that do not train theirs. Where a provider offers it, SyftOS can request zero data retention.
UK data residency
The core application, database, cache and file storage are hosted in the United Kingdom. Where data is processed abroad (for example by AI providers), transfers are covered by the UK Addendum to the EU Standard Contractual Clauses.
See the detail
The documents behind these commitments.
Security & Trust Statement
The full control summary for procurement and due diligence.
AI Data Use Statement
Exactly how SyftOS uses AI and your data.
Sub-processor List
Every provider that may process data, with locations and safeguards.
Data Processing Agreement
Our processor commitments under UK GDPR Article 28.
Status
Live platform availability and incident history.
Want a closer look?
Book a 30-minute demo on your own tools, or ask for a security review — we will walk you through the Approval Centre, the audit trail and how your data is handled.