Local evaluation
Suitable for architecture review and synthetic scenarios that contain no customer or personal data.
Synaporia is designed to give organisations a consistent way to set boundaries, protect sensitive work, require human judgement and review how an AI-assisted decision was handled.
Working software is not the same as a qualified service. We use controlled maturity states so buyers can distinguish a local capability from a deployed and independently tested one.
Suitable for architecture review and synthetic scenarios that contain no customer or personal data.
Not permitted until the remaining identity, evidence, infrastructure, legal and operating checks are completed.
No production service, guaranteed service level, certification or deployed region is represented.
Assessment boundary: the governed capability ledger distinguishes integrated, locally built, designed and absent controls. No capability is represented as pilot- or production-verified; current counts remain machine-governed in the repository rather than copied into this page where they could become stale.
The intended control path checks the organisation's rules before meaningful work proceeds.
Sensitive actions are designed to pause for an authorised person and, where required, a second approver.
Purpose, sensitivity and location are treated as decision inputs, not afterthoughts.
The intended record connects the request, applicable boundaries, human decision and outcome.
Missing context, stale information or an unavailable safeguard should deny or escalate higher-risk work.
Rapid, Standard, Protected, Governed and Critical are operation-level control bundles—not permanent labels for an industry or company. Context and authoritative policy establish the minimum.
Core safety and cost limits; no privileged effect.
Authenticated context and bounded read-only assistance.
Least disclosure, grounding and confirmation before effect.
Independent challenge, evidence and named human authority.
Independent review, dual control and stop on disagreement.
The design has been compared with selected themes in NIST AI RMF, ISO/IEC 42001, the EU AI Act, GDPR and Kenya's Data Protection Act. These mappings support review but do not establish compliance, certification or regulatory approval.
We can map who decides, which information may be used, what the AI must never do alone and what evidence your reviewers need.
Request a trust workshopEmail security@synaporia.io with a concise description, affected surface and safe reproduction steps. Do not include customer data, credentials or destructive proof. Receipt and remediation timelines are not yet represented as a production SLA.