Autonomy, with a handbrake.
Handing work to software is a question of control, not enthusiasm. Here is exactly what Systeni does, what it refuses to do on its own, and — further down — what we do not yet hold.
How autonomy is bounded.
Agents act inside limits you set
Policy rules decide what an agent may do alone: an amount band, a minimum confidence and who approves. Outside those limits, a person decides.
Answers come from approved sources
The knowledge base is what you upload and approve. Agents cite the source, and say they do not know rather than inventing an answer.
Everything is reversible
Workflows are versioned, agents can be paused in one click, and every run keeps a record of each step it took.
Nothing goes live until you publish
Workflows run against sample traffic in test mode first. No customer sees anything you have not watched work.
What is true right now.
Everything on this list is implemented and can be verified in the product or in a contract.
- Encryption in transitHTTPS on every connection, with HSTS so a browser that has visited once will not fall back to plain HTTP.
- Where the data isOne server, in Nuremberg, Germany. Not a choice of regions — there is one, and this is it. If you need it somewhere else, we hand you a copy you run yourself.
- Role-based access controlOwner, admin, operator and viewer, enforced per workspace.
- Human handoff by designAn answer the documents do not support, or one below a fixed confidence floor, goes to a person. The confidence an action needs is set per policy rule.
What we do not have.
Most vendors leave this page out. If a certification appears on a competitor's site, ask for the report — and hold us to the same standard.
- Not held
GDPR processing agreement
In preparation. Sub-processors are listed on the privacy page and deletion requests are answered within 30 days, but there is no signed processing agreement yet.
- Not held
Audit log
Recorded; customer export not yet available. Sign-ins, connection, policy and workflow changes are written to an audit table on the server, and there is no screen or export for you to read it yet.
- Not held
SOC 2 Type II
Not yet held. On the roadmap; we will publish the report when it exists.
- Not held
ISO 27001
Not yet held. Scoped, not certified.
- Not held
Published uptime SLA
Contractual SLA offered on Enterprise. No public status page yet.
- Not held
Encryption at rest
Not yet. The database volume and the nightly backups are not encrypted at rest. Credentials a workspace stores for its connections are sealed separately, with AES-256-GCM.
Bring your security questionnaire.
We complete it before commercials, not after — and where the honest answer is "not yet", that is the answer you get.