Security & Governance
Sylaxis Trust Center
Security, data privacy, and strict tenant isolation are not afterthought features of our platform, but our architectural foundation. Sylaxis was designed from the ground up as a multi-tenant enterprise AI work platform that protects sensitive corporate data in accordance with the strictest European data protection and security standards.
Here you will find a transparent overview of our implemented security measures, cryptographic standards, and governance policies.
Security Architecture Overview
Sylaxis employs a multi-layered security model (Defense in Depth), where every access layer is independently validated and isolated.

1. Tenant Isolation & Database Security
Logical isolation of all tenant data at Sylaxis is enforced directly within the database core across four independent control layers:
| Protection Layer | Mechanism | Technical Enforcement |
|---|---|---|
| Layer 1: Query Isolation | PostgreSQL Row-Level Security (RLS) | Every table enforces strict tenant filters with mandatory WITH CHECK clauses across all read and write operations. |
| Layer 2: Creation Guarantee | Server-Side Insert Triggers | Automatically overwrites any tenant ID provided by the client with the cryptographically verified session identity on the server. |
| Layer 3: Immutability Guarantee | Server-Side Update Triggers | Prevents any retroactive modification of tenant assignment at the database level. Tenant hopping is technically impossible. |
| Layer 4: Referential Integrity | Foreign Key Constraints | Enforces strict relational validity across all tenant structures directly inside the database engine. |
| Additional Control | FORCE ROW LEVEL SECURITY | RLS is enforced on all production tables without exception—policies apply unconditionally even in administrative contexts. |
2. Cryptography & Envelope Encryption
All data at rest and in transit is protected according to state-of-the-art cryptographic standards:
- Transport Encryption (In-Transit): End-to-end TLS 1.3 with modern cipher suites, HSTS (HTTP Strict Transport Security), and strict HTTPS enforcement.
- Storage Encryption (At-Rest): Full AES-256 encryption across all databases, indexes, and object storage.
- Three-Tier Key Hierarchy for Sensitive PII Data:
- Data Encryption Key (DEK): Client-side encryption of sensitive entity mappings directly in the browser via AES-256-GCM prior to transmission.
- Tenant Key Encryption Key (KEK): Each tenant has a cryptographically isolated KEK used to securely persist DEKs.
- Master Encryption Key (MEK): The Tenant KEK is protected by a highly secured 256-bit platform-level Master Key.
Zero-Knowledge Principle: Sensitive plaintext mappings cannot be viewed even by administrative system layers.
3. AI Governance, DLP & Data Protection
Sylaxis enables the productive deployment of cutting-edge enterprise AI models while maintaining complete corporate confidentiality and GDPR compliance:
- Zero Model Training with Customer Data (Zero-Training):
Neither prompts, uploaded enterprise documents, nor generated responses are used to train public or proprietary base models (SLA-backed).
- Gemini Enterprise Agent Platform Safety Gates (formerly Vertex AI):
- All model invocations are routed through Google Cloud's enterprise infrastructure with server-side enforced safety filters (default: Block Medium and Above).
- Reliable detection and blocking of toxic content, harmful instructions, and unsafe outputs.
- Protection Against Prompt Injections & Sanitization:
- Multi-stage filtering to defend against system prompt leaks, role manipulations (jailbreaks), and secondary injection attacks.
- Automated sanitization of all model and rich-text outputs against cross-site scripting (XSS).
- Optional DLP & Pseudonymization Engine (Opt-In during Upload):
- Volatile In-Memory Processing (Zero Persistence & Zero Logs): Detection and masking of personally identifiable information (PII such as names, IBANs, tax IDs, addresses) occurs in isolated, stateless containers entirely in volatile memory without persistent storage or logging.
- Interactive Approval (Human-in-the-Loop): Users receive a transparent overview of masked entities before processing and retain full control.
- Exclusive Re-Identification: The encrypted mapping table remains isolated and can only be decrypted by the authorized user.
- Integrated Malware Analysis: Every uploaded document undergoes automated virus and malware scanning before processing and indexing.
4. Identity, Permissions & Access Control
- Granular 3-Tier Permission Architecture (Least Privilege):
- Tier 1 (Tenant Role): Strict role separation within the tenant (Administrator, Editor, User) with no implicit permissions on third-party data.
- Tier 2 (Feature Capabilities): Modular assignment of platform features and module permissions.
- Tier 3 (Entity-Level Whitelists): Explicit permission assignment for documents, knowledge spaces (Spaces), AI agents, and files, including virtual user groups.
- Server-Enforced Multi-Factor Authentication (MFA / AAL2): Critical corporate resources and administrative interfaces enforce Authenticator Assurance Level 2 (AAL2 via TOTP).
- Protection Against Side-Channel & Timing Attacks: Authentication tokens, CSRF tokens, and API signatures are validated using cryptographic constant-time operations.
- Modern Session Management: Short-lived JWT access tokens with automated refresh token rotation and OAuth 2.1 with PKCE for browser extensions.
5. Network Security, API Hardening & DevSecOps
- Intelligent Rate Limiting: Persistent, token-based rate limiting with SHA-256-hashed scopes to protect against DoS and brute-force attacks.
- SSRF Protection & DNS Rebinding Filtering: Strict validation of outbound interfaces, including automatic blocking of private IP ranges (RFC 1918, IPv6 ULA) and cloud metadata endpoints.
- Cryptographically Signed Webhooks: Replay protection through HMAC-SHA256 signatures with timestamps and nonce validation.
- Automated Security Gates in CI/CD (Shift-Left DevSecOps):
- Shift-Left Secret Protection & Pre-Commit Gates: Automated scanners cryptographically and heuristically prevent credentials, API keys, or service tokens from entering source repositories – directly at the developer level prior to each Git commit.
- Continuous Source Code Analysis (SAST & Policy Linting): In-depth static analyses (including GitHub CodeQL and specialized security rulesets) detect taint flows, ReDoS risks, and injection vectors. Dedicated database linters verify the seamless enforcement of Row-Level Security (RLS) and secure function definitions before every release.
- Behavioral Supply Chain Security (SCA): Advanced verification of third-party libraries for malicious code, typosquatting, and suspicious network activity during installation and build stages, well beyond reactive CVE lookups.
- Dynamic Application Security Testing (DAST): Regular automated scans of staging and API infrastructure evaluating HTTP security headers (HSTS, CSP), CORS configurations, and TLS compliance (OWASP standards).
- Audit-Proof Logging & Soft Deletes: Changes to core entities and security configurations are immutably logged. Multi-stage logical deletion concepts protect against accidental data loss.
6. Compliance, Data Residency & Certification Roadmap
- 100% Data Residency & Processing in the European Union:
- Primary Database, Authentication & Edge Functions (Supabase / AWS): Frankfurt am Main, Germany (
eu-central-1). - Application & DLP Microservices (Google Cloud Run): Frankfurt am Main, Germany (
europe-west3). - Document & File Storage (Google Cloud Storage): European Union (EU) multi-region.
- Enterprise AI Inference & Embeddings (Google Gemini Enterprise): European Union (EU) multi-region.
- Primary Database, Authentication & Edge Functions (Supabase / AWS): Frankfurt am Main, Germany (
- GDPR Compliance & EU AI Act Readiness:
- Consistent implementation of Privacy by Design and Privacy by Default (Art. 25 GDPR) as well as appropriate technical and organizational measures (Art. 32 GDPR).
- Standardized Data Processing Agreement (DPA / AVV) including detailed technical and organizational measures (TOMs).
- Automated workflows to fulfill data subject rights (access under Art. 15/20 GDPR and cascading deletion under Art. 17 GDPR).
- Compliance for Professional Secret Carriers (Sec. 203 StGB, Sec. 62a StBerG, Sec. 43e BRAO & Sec. 50a WPO):
Sylaxis is designed for legally compliant deployment in practices of tax advisors, certified public accountants, and law firms bound by professional confidentiality:
- Assisting Person (Cooperating Third Party): Sylaxis acts as an assisting person within the meaning of Sec. 203(3) sentence 2 of the German Criminal Code (StGB) and relevant professional codes (Sec. 62a StBerG / Sec. 43e BRAO / Sec. 50a WPO).
- Penal Confidentiality Obligation: All employees and vicarious agents with potential administrative access are formally bound to confidentiality and instructed on the criminal penalties under Sec. 203(4) StGB.
- Zero-Training & EU Data Residency: Contractually guaranteed zero-training and data processing strictly within certified European Union data centers (including database & microservices in Frankfurt am Main as well as file storage & AI inference in the EU multi-region) safeguard client privilege at all times.
- Dedicated Law Firm Addendum: In the customer dashboard, we provide a specialized “Agreement on the Protection of Professional Secrets (Sec. 203 StGB / Sec. 62a StBerG)” alongside the standard DPA.
- Availability & Disaster Recovery:
- Daily automated backups and Point-in-Time Recovery (PITR).
- High resilience through geo-redundant storage within the EU.
- Certifications of Underlying Cloud Infrastructure:
The physical data centers and foundational cloud services of our partners are audited and certified according to top industry standards:
ISO/IEC 27001ISO/IEC 27017ISO/IEC 27018SOC 1SOC 2 Type IISOC 3BSI C5TISAX - Sylaxis Security Governance & Certification Roadmap:
Sylaxis develops and operates all software services following the established control objectives of ISO/IEC 27001, BSI IT-Grundschutz, and the OWASP Top 10 framework (Security & Privacy by Design).
Compliance Roadmap: Formal company-level certifications (ISO/IEC 27001 and SOC 2 Type II) are on our strategic roadmap and will be audited as the company scales.
Transparency & Vendor Audits: For security assessments and vendor reviews, we gladly provide enterprise customers upon request with our standardized security questionnaires (e.g., CAIQ / VSAQ) and our comprehensive TOM catalog (team@sylaxis.com).