§ Arkheia Synesis · Compliance

When your auditor asks for AI evidence,
you generate it in 30 seconds.

EU AI Act. NIST AI RMF. ISO 42001. SOC 2. GDPR. Every framework requires evidence that your AI systems are under control. Synesis produces that evidence continuously — not when an audit is scheduled, but every day your systems run.

§ What Generates the Evidence

Every control maps directly to a regulatory article.

The compliance map is not a claim. It is a live record of what Synesis does and which requirement each action satisfies.

EU AI Act · Article 13

Transparency & Logging

COMPLIANT

EU AI Act · Article 14

Human Oversight

PARTIAL

EU AI Act · Article 9

Risk Management System

COMPLIANT

NIST AI RMF · GOVERN 1.1

Policies and Processes

COMPLIANT

GDPR · Article 32

Security of Processing

PARTIAL

Report generation: One click. Any framework. Any date range. Any workflow. The report is dated, scoped, and formatted for external submission. Auditors do not need access to the platform.

§ Arkheia Synesis · Operational Control

One number tells you where your AI governance stands.
Three actions tell you what to fix next.

This is not a dashboard. It is a prioritised work queue for your security team. Every dimension scored. Every gap surfaced. Every action worth a specific number of points.

Enter the live environment at synesis.arkheia.ai →
synesis · governance overview · live⚠ AT RISK

34.29

Governance Posture · At Risk

Governance
25
Data
16
Operational
13
Integrity
11
Perimeter
8

Improvement Opportunities

+9 pts recoverable
PERIMETER

Agent certification drift — 4 agents running outside their approved image version

+4 pts
OPERATIONAL

Tool pending approval — Browser Controller is unapproved

+3 pts
INTEGRITY

Guardrail bypass signals open — Unresolved integrity signals penalising score

+2 pts

§ Five Dimensions

What each dimension scores — and why it matters.

25/ 40

Governance

Policy compliance, agent certification, tool approval

16/ 20

Data

PII detection rate, data classification breach, RAG breach rate 0.083%

13/ 20

Operational

Spend within limits, token anomalies, loop depth controls

11/ 25

Integrity

Guardrail bypass signals open, risk spikes unresolved

8/ 25

Perimeter

Prompt injection signals, unauthorized model access — most exposed

01

8

active policies

HARD: Unauthorised model block — EU AI Act, NIST AI RMF, ISO 42001

HARD: No RESTRICTED data in public workflows — EU AI Act, GDPR

HARD: Tool risk score threshold — OWASP Agentic, NIST AI RMF

SOFT: PII detection for CONFIDENTIAL workflows — GDPR, SOC2

Policy Engine

Eight policy types. Hard enforcement blocks the invocation before the model receives the request. Soft enforcement fires a signal for human review. Every policy tagged to the regulatory framework it satisfies.

The policy table is a compliance artefact, not just operational configuration. Auditors can see exactly which control maps to which requirement.

02

9

agents registered

RESTRICTED 2 · SUPERVISED 5 · SEMI-AUTONOMOUS 2

Customer Support Bot — REVOKED · Untrusted Agent — REVOKED

Legal Review Agent — ACTIVE · Dev Assistant — SEMI-AUTONOMOUS

Per-agent: Revoke or Re-authorise in one click

Agent Registry

Every AI agent registered with identity, autonomy tier, authorisation trail, and operational status. Nothing runs without a registered profile. Nothing stays running if it drifts from it.

Revoke or re-authorise in one action. Autonomy tiers — RESTRICTED, SUPERVISED, SEMI-AUTONOMOUS — determine what agents are permitted to do without human approval.

03

<5s

propagation via NATS

OPERATIONAL status displayed at all times on the page

Scoped fire: MODEL · WORKFLOW · AGENT · MCP_SERVER · TENANT

Reason required — every fire is an audit trail entry

Kill Journal: immutable historical record of all fire events

Kill Switch

Scope: all models, specific model, specific workflow, specific agent, MCP server. One reason field required for audit trail. Kill Journal records every fire event immutably.

The button is not buried in settings. It is always visible. OPERATIONAL status shown prominently — when nothing is suspended, you see it immediately. When you need to act, one click from any screen.

04

41

signals · one day

UNAUTHORIZED_MODEL · CRITICAL · GOVERNANCE

PROMPT_INJECTION_DETECTED · CRITICAL · PERIMETER

GUARDRAIL_BYPASS · HIGH · GOVERNANCE

PII_DETECTED · HIGH and MEDIUM · DATA

Operations — Live Signal Feed

Real-time. Filterable by severity and category. Every signal timestamped, categorised, and waiting for a human decision: Acknowledge or escalate. Not an alert. A fact.

41 signals on a single operating day. Each one is evidence. UNAUTHORIZED_MODEL. PROMPT_INJECTION_DETECTED. GUARDRAIL_BYPASS. Every one waiting for a human decision.

05

88.9%

fleet certified

Legal Review Agent — UNCERTIFIED — Re-certify button live

Trust Zones: Public (2 entities) · Internal (4) · Restricted (1)

RAG: 4 sources · 2 policy breaches · 0.083% breach rate

2 orphaned entities — ungoverned, flagged for action

Fleet & Frontier Governance

Agents assessed against golden images on a schedule. Trust Zone Topology: Zone 1 Public, Zone 2 Internal, Zone 3 Restricted. RAG governance: knowledge sources monitored for policy breach rate.

Orphaned entities flagged immediately. Legal Review Agent — UNCERTIFIED — one click to re-certify. Nothing runs without a zone. Nothing stays running if it drifts.

§ Deployment

Run it your way

Self-hosted

Docker Compose

git clone + make demo = live governance dashboard in under 2 minutes. Zero external dependencies.

Enterprise

Kubernetes / Helm

Enterprise-grade deployment with Helm charts. Horizontal scaling, rolling updates, and full observability.

Maximum Security

Air-Gapped

Complete offline deployment. No internet access required. Runs entirely within your network boundary.

The live environment is open.
See the posture score. Generate a report. Fire the kill switch.

Log in, check the posture score, follow an improvement opportunity, generate a compliance report in one click. The demo data is from a real simulated AI estate. It resets daily.