Built for teams that read the fine print.
Security posture, public documentation, and the full catalogue of native integrations — everything you'd want to send to your CISO, your platform team, and your CIO before you commit.
Built with zero-trust from day one.
Synapse runs the kind of workloads where a leak is a business event, not an annoyance. We design as if every interface — UI, API, agent-to-agent, service-to-service — is untrusted. Every action is logged, every key is encrypted, every tenant is isolated at the database boundary.
Built to meet the standards of the most regulated industries — financial services, healthcare, public sector — without slowing teams down.
Controls implemented and internally audited; independent audit not yet engaged
DPA + SCCs available; rights center built in
Consent management, data export, and deletion built in
Contact us about regulated workloads
Targeted 2027
Not required for current workloads
Independent test before general availability
At rest + TLS 1.3 in transit
Not a policy document. The controls, working.
Two hundred connectors with a plain-English preview of what each one can read and write. Three roles and forty permission keys, overridable per person. Policy gates and approval chains on anything high-impact, an immutable audit trail, an undo window — and every token of AI usage metered against budgets you set by team and by agent, enforced hard.
Controls in detail
Tenant isolation
Postgres Row-Level Security at the database boundary. Every row carries an organization_id and queries are scoped automatically. Multi-tenant SaaS with strict row-level isolation per organization.
Identity & access
Role-based access control, MFA, session enforcement, and brute-force lockout today. Three roles and a forty-key permission matrix, overridable per person. SAML SSO and SCIM provisioning are on the Enterprise roadmap.
Encryption & key custody
Encryption at rest and in transit (TLS 1.3). LLM provider keys (OpenAI, Anthropic, Bedrock, Azure, Gemini) and connector tokens are sealed in an AES-256-GCM encrypted vault. Only the LLM gateway ever decrypts them.
Audit trail
Every meaningful action is logged with actor, timestamp, request id, and signed metadata. Connector actions and agent decisions carry their approvals. Audit packages are exportable for compliance review.
Approval workflows
Human-in-the-loop gates on configurable thresholds, with multi-approver policies available. High-impact actions pause for explicit approval before they execute. Override anything an agent does, with the diff captured as feedback to the system.
Zero-trust by default
Every internal service-to-service call requires shared-secret auth. No implicit trust between agents, workers, or stores.
AI governance
Customer data is never used for model training. Never visible to other tenants. Bring-your-own-LLM endpoints supported, and every token of usage is metered against budgets you set.
Deployment & data residency
US-hosted today on managed cloud infrastructure. EU residency and dedicated deployment options are on the Enterprise roadmap.
How we earn the right to your most important data.
Boundary by default
Your data never leaves your tenant. Memory, models, and decisions are partitioned per customer with row-level security enforced at the database.
Explainable by construction
Actions are logged with the actor, input context, and approvals involved, so you can reconstruct what happened and why.
Approved before impact
High-impact actions pause in an approval queue until a human signs off — nothing irreversible happens silently.
Need the full security packet?
Our security overview, current SOC 2 progress summary, and answers to your vendor questionnaire are available to qualified prospects under NDA.
Every system needs a map.
Public documentation is being staged with our first design partners. Until the full docs site is live, the entry points below cover the highest-leverage reading.
Quick Start
Getting startedGet an agent running on a sandbox workspace — during preview, the founding team walks you through setup directly.
Open →Architecture Guide
ConceptsHow Synapse is composed — the agent runtime, memory plane, decision plane, and orchestrator.
Open →Agent Templates
ReferenceEvery shipped template, what tools it uses, and how to fork it.
Open →Mobile App
Coming sooniOS + Android — currently in development. Approval queues, run history, and agent control from anywhere are coming soon.
Open →Talks to everything your business already runs on.
The full catalogue is 210 systems, and they are not all at the same stage — so they aren't shown that way. Below, every connector sits under a heading that says exactly how far along it is, from signed in and running in production to on the roadmap. Anything with a REST, GraphQL, or webhook surface can be connected today regardless of what this list says.
Every provider below is wired into the model gateway — pick one per agent, or bring your own API key and we meter against it. Nothing is locked to a single vendor: switching an agent to a different model is a dropdown, and the cost of every run is recorded against whichever provider served it.
Claude — the default for agent reasoning and long-context work.
GPT models, including the cost-efficient mini tiers.
Gemini — strong multimodal and very large context windows.
Search-grounded answers with live citations.
European models, open weights, EU data residency.
Very low cost per token for high-volume batch work.
Grok, with real-time context from X.
On the roadmap: AWS Bedrock · Self-hosted — the gateway has no adapter for these yet, so they aren't listed above.
Connected in production — a real sign-in has completed with a real account. Split below by whether an agent can act on it yet.
Signed in, and an agent tool reaches it — these are the connections your agents can actually read from and write to right now.
The connection is real and stored, but no agent tool targets it yet. Some of these surfaces are reachable through their parent connection (Calendar and Docs via Google Workspace, for example); as a standalone connection they are not something an agent can act on today.
Built and registered with the vendor. Available to design partners now; a few are waiting on the provider’s own app review before they open to everyone.
The integration is written and tested against the vendor’s API. Waiting on app registration and review, which is a matter of days per connector once a customer needs it.
On the roadmap. Anything with a REST, GraphQL, or webhook surface can also be connected today with the custom connector builder — tell us the system and we’ll prioritize it.
Brand marks via Simple Icons (CC0) and Font Awesome Free (CC BY 4.0). All product names, logos, and brands are the property of their respective owners and are used here to identify integrations — their use does not imply endorsement.
Don't see a system you use?
Anything with a REST, GraphQL, or webhook surface integrates in a day or two. Bring us your stack.
Stop renting intelligence.
Build it.
Neivan is in private preview with select teams. We're admitting a small cohort each month.