§ Arkheia Synesis · Compliance
When your auditor asks for AI evidence,
you generate it in 30 seconds.
EU AI Act. NIST AI RMF. ISO 42001. SOC 2. GDPR. Every framework requires evidence that your AI systems are under control. Synesis produces that evidence continuously — not when an audit is scheduled, but every day your systems run.
§ What Generates the Evidence
Every control maps directly to a regulatory article.
The compliance map is not a claim. It is a live record of what Synesis does and which requirement each action satisfies.
EU AI Act · Article 13
Transparency & Logging
EU AI Act · Article 14
Human Oversight
EU AI Act · Article 9
Risk Management System
NIST AI RMF · GOVERN 1.1
Policies and Processes
GDPR · Article 32
Security of Processing
Report generation: One click. Any framework. Any date range. Any workflow. The report is dated, scoped, and formatted for external submission. Auditors do not need access to the platform.
§ Arkheia Synesis · Operational Control
One number tells you where your AI governance stands.
Three actions tell you what to fix next.
This is not a dashboard. It is a prioritised work queue for your security team. Every dimension scored. Every gap surfaced. Every action worth a specific number of points.
Enter the live environment at synesis.arkheia.ai →34.29
Governance Posture · At Risk
Improvement Opportunities
+9 pts recoverableAgent certification drift — 4 agents running outside their approved image version
+4 ptsTool pending approval — Browser Controller is unapproved
+3 ptsGuardrail bypass signals open — Unresolved integrity signals penalising score
+2 pts§ Five Dimensions
What each dimension scores — and why it matters.
Governance
Policy compliance, agent certification, tool approval
Data
PII detection rate, data classification breach, RAG breach rate 0.083%
Operational
Spend within limits, token anomalies, loop depth controls
Integrity
Guardrail bypass signals open, risk spikes unresolved
Perimeter
Prompt injection signals, unauthorized model access — most exposed
01
8
active policies
HARD: Unauthorised model block — EU AI Act, NIST AI RMF, ISO 42001
HARD: No RESTRICTED data in public workflows — EU AI Act, GDPR
HARD: Tool risk score threshold — OWASP Agentic, NIST AI RMF
SOFT: PII detection for CONFIDENTIAL workflows — GDPR, SOC2
Policy Engine
Eight policy types. Hard enforcement blocks the invocation before the model receives the request. Soft enforcement fires a signal for human review. Every policy tagged to the regulatory framework it satisfies.
The policy table is a compliance artefact, not just operational configuration. Auditors can see exactly which control maps to which requirement.
02
9
agents registered
RESTRICTED 2 · SUPERVISED 5 · SEMI-AUTONOMOUS 2
Customer Support Bot — REVOKED · Untrusted Agent — REVOKED
Legal Review Agent — ACTIVE · Dev Assistant — SEMI-AUTONOMOUS
Per-agent: Revoke or Re-authorise in one click
Agent Registry
Every AI agent registered with identity, autonomy tier, authorisation trail, and operational status. Nothing runs without a registered profile. Nothing stays running if it drifts from it.
Revoke or re-authorise in one action. Autonomy tiers — RESTRICTED, SUPERVISED, SEMI-AUTONOMOUS — determine what agents are permitted to do without human approval.
03
<5s
propagation via NATS
OPERATIONAL status displayed at all times on the page
Scoped fire: MODEL · WORKFLOW · AGENT · MCP_SERVER · TENANT
Reason required — every fire is an audit trail entry
Kill Journal: immutable historical record of all fire events
Kill Switch
Scope: all models, specific model, specific workflow, specific agent, MCP server. One reason field required for audit trail. Kill Journal records every fire event immutably.
The button is not buried in settings. It is always visible. OPERATIONAL status shown prominently — when nothing is suspended, you see it immediately. When you need to act, one click from any screen.
04
41
signals · one day
UNAUTHORIZED_MODEL · CRITICAL · GOVERNANCE
PROMPT_INJECTION_DETECTED · CRITICAL · PERIMETER
GUARDRAIL_BYPASS · HIGH · GOVERNANCE
PII_DETECTED · HIGH and MEDIUM · DATA
Operations — Live Signal Feed
Real-time. Filterable by severity and category. Every signal timestamped, categorised, and waiting for a human decision: Acknowledge or escalate. Not an alert. A fact.
41 signals on a single operating day. Each one is evidence. UNAUTHORIZED_MODEL. PROMPT_INJECTION_DETECTED. GUARDRAIL_BYPASS. Every one waiting for a human decision.
05
88.9%
fleet certified
Legal Review Agent — UNCERTIFIED — Re-certify button live
Trust Zones: Public (2 entities) · Internal (4) · Restricted (1)
RAG: 4 sources · 2 policy breaches · 0.083% breach rate
2 orphaned entities — ungoverned, flagged for action
Fleet & Frontier Governance
Agents assessed against golden images on a schedule. Trust Zone Topology: Zone 1 Public, Zone 2 Internal, Zone 3 Restricted. RAG governance: knowledge sources monitored for policy breach rate.
Orphaned entities flagged immediately. Legal Review Agent — UNCERTIFIED — one click to re-certify. Nothing runs without a zone. Nothing stays running if it drifts.
§ Deployment
Run it your way
Docker Compose
git clone + make demo = live governance dashboard in under 2 minutes. Zero external dependencies.
Kubernetes / Helm
Enterprise-grade deployment with Helm charts. Horizontal scaling, rolling updates, and full observability.
Air-Gapped
Complete offline deployment. No internet access required. Runs entirely within your network boundary.
The live environment is open.
See the posture score. Generate a report. Fire the kill switch.
Log in, check the posture score, follow an improvement opportunity, generate a compliance report in one click. The demo data is from a real simulated AI estate. It resets daily.