Security & trust

Autonomy, with a handbrake.

Handing work to software is a question of control, not enthusiasm. Here is exactly what Systeni does, what it refuses to do on its own, and — further down — what we do not yet hold.

Control

How autonomy is bounded.

Agents act inside limits you set

Policy rules decide what an agent may do alone: an amount band, a minimum confidence and who approves. Outside those limits, a person decides.

Answers come from approved sources

The knowledge base is what you upload and approve. Agents cite the source, and say they do not know rather than inventing an answer.

Everything is reversible

Workflows are versioned, agents can be paused in one click, and every run keeps a record of each step it took.

Nothing goes live until you publish

Workflows run against sample traffic in test mode first. No customer sees anything you have not watched work.

In place today

What is true right now.

Everything on this list is implemented and can be verified in the product or in a contract.

  • Encryption in transitHTTPS on every connection, with HSTS so a browser that has visited once will not fall back to plain HTTP.
  • Where the data isOne server, in Nuremberg, Germany. Not a choice of regions — there is one, and this is it. If you need it somewhere else, we hand you a copy you run yourself.
  • Role-based access controlOwner, admin, operator and viewer, enforced per workspace.
  • Human handoff by designAn answer the documents do not support, or one below a fixed confidence floor, goes to a person. The confidence an action needs is set per policy rule.
Not yet

What we do not have.

Most vendors leave this page out. If a certification appears on a competitor's site, ask for the report — and hold us to the same standard.

  • Not held

    GDPR processing agreement

    In preparation. Sub-processors are listed on the privacy page and deletion requests are answered within 30 days, but there is no signed processing agreement yet.

  • Not held

    Audit log

    Recorded; customer export not yet available. Sign-ins, connection, policy and workflow changes are written to an audit table on the server, and there is no screen or export for you to read it yet.

  • Not held

    SOC 2 Type II

    Not yet held. On the roadmap; we will publish the report when it exists.

  • Not held

    ISO 27001

    Not yet held. Scoped, not certified.

  • Not held

    Published uptime SLA

    Contractual SLA offered on Enterprise. No public status page yet.

  • Not held

    Encryption at rest

    Not yet. The database volume and the nightly backups are not encrypted at rest. Credentials a workspace stores for its connections are sealed separately, with AES-256-GCM.

Systeni is early. Until these exist, we will not display a badge for them, and no salesperson is authorised to imply otherwise. If a certification is a hard requirement for your procurement, tell us now rather than at contract stage.

Bring your security questionnaire.

We complete it before commercials, not after — and where the honest answer is "not yet", that is the answer you get.