Autonomy, with a handbrake.
Handing work to software is a question of control, not enthusiasm. Here is exactly what Systeni does, what it refuses to do on its own, and — further down — what we do not yet hold.
How autonomy is bounded.
Agents act inside limits you set
Each agent has a confidence threshold, an escalation rule and a value ceiling. Below the threshold or above the ceiling, a person decides.
Answers come from approved sources
The knowledge base is what you upload and approve. Agents cite the source, and say they do not know rather than inventing an answer.
Everything is reversible
Workflows are versioned, agents can be paused in one click, and the audit log records every configuration change and every action taken.
Nothing goes live until you publish
Workflows run against sample traffic in test mode first. No customer sees anything you have not watched work.
What is true right now.
Everything on this list is implemented and can be verified in the product or in a contract.
- Encryption in transit and at restTLS 1.3 on every connection; volumes encrypted at rest.
- EU data residencyHosted in the EU by default. Enterprise can pin a region or self-host.
- GDPR processing agreementDPA available, sub-processors listed, deletion honoured on request.
- Role-based access controlOwner, admin, operator and viewer, enforced per workspace.
- Audit logEvery configuration change and agent action recorded and exportable.
- Human handoff by designAgents escalate below a confidence threshold you control.
What we do not have.
Most vendors leave this page out. If a certification appears on a competitor's site, ask for the report — and hold us to the same standard.
- SOC 2 Type IINot held
Not yet held. On the roadmap; we will publish the report when it exists.
- ISO 27001Not held
Not yet held. Scoped, not certified.
- Published uptime SLANot held
Contractual SLA offered on Enterprise. No public status page yet.
Bring your security questionnaire.
We complete it before commercials, not after. Enterprise adds data residency, private deployment, SSO and a contractual SLA.