Skip to content

Security & Governance

Sylaxis Trust Center

Security, data privacy, and strict tenant isolation are not afterthought features of our platform, but our architectural foundation. Sylaxis was designed from the ground up as a multi-tenant enterprise AI work platform that protects sensitive corporate data in accordance with the strictest European data protection and security standards.

Here you will find a transparent overview of our implemented security measures, cryptographic standards, and governance policies.

Security Architecture Overview

Sylaxis employs a multi-layered security model (Defense in Depth), where every access layer is independently validated and isolated.

Sylaxis Security and Tenant Architecture Overview
Figure: Multi-layered security model of Sylaxis – from the client layer to cryptographic tenant isolation.

1. Tenant Isolation & Database Security

Logical isolation of all tenant data at Sylaxis is enforced directly within the database core across four independent control layers:

Protection LayerMechanismTechnical Enforcement
Layer 1: Query IsolationPostgreSQL Row-Level Security (RLS)Every table enforces strict tenant filters with mandatory WITH CHECK clauses across all read and write operations.
Layer 2: Creation GuaranteeServer-Side Insert TriggersAutomatically overwrites any tenant ID provided by the client with the cryptographically verified session identity on the server.
Layer 3: Immutability GuaranteeServer-Side Update TriggersPrevents any retroactive modification of tenant assignment at the database level. Tenant hopping is technically impossible.
Layer 4: Referential IntegrityForeign Key ConstraintsEnforces strict relational validity across all tenant structures directly inside the database engine.
Additional ControlFORCE ROW LEVEL SECURITYRLS is enforced on all production tables without exception—policies apply unconditionally even in administrative contexts.

2. Cryptography & Envelope Encryption

All data at rest and in transit is protected according to state-of-the-art cryptographic standards:

  • Transport Encryption (In-Transit): End-to-end TLS 1.3 with modern cipher suites, HSTS (HTTP Strict Transport Security), and strict HTTPS enforcement.
  • Storage Encryption (At-Rest): Full AES-256 encryption across all databases, indexes, and object storage.
  • Three-Tier Key Hierarchy for Sensitive PII Data:
    1. Data Encryption Key (DEK): Client-side encryption of sensitive entity mappings directly in the browser via AES-256-GCM prior to transmission.
    2. Tenant Key Encryption Key (KEK): Each tenant has a cryptographically isolated KEK used to securely persist DEKs.
    3. Master Encryption Key (MEK): The Tenant KEK is protected by a highly secured 256-bit platform-level Master Key.
    Zero-Knowledge Principle: Sensitive plaintext mappings cannot be viewed even by administrative system layers.

3. AI Governance, DLP & Data Protection

Sylaxis enables the productive deployment of cutting-edge enterprise AI models while maintaining complete corporate confidentiality and GDPR compliance:

  • Zero Model Training with Customer Data (Zero-Training):

    Neither prompts, uploaded enterprise documents, nor generated responses are used to train public or proprietary base models (SLA-backed).

  • Gemini Enterprise Agent Platform Safety Gates (formerly Vertex AI):
    • All model invocations are routed through Google Cloud's enterprise infrastructure with server-side enforced safety filters (default: Block Medium and Above).
    • Reliable detection and blocking of toxic content, harmful instructions, and unsafe outputs.
  • Protection Against Prompt Injections & Sanitization:
    • Multi-stage filtering to defend against system prompt leaks, role manipulations (jailbreaks), and secondary injection attacks.
    • Automated sanitization of all model and rich-text outputs against cross-site scripting (XSS).
  • Optional DLP & Pseudonymization Engine (Opt-In during Upload):
    • Volatile In-Memory Processing (Zero Persistence & Zero Logs): Detection and masking of personally identifiable information (PII such as names, IBANs, tax IDs, addresses) occurs in isolated, stateless containers entirely in volatile memory without persistent storage or logging.
    • Interactive Approval (Human-in-the-Loop): Users receive a transparent overview of masked entities before processing and retain full control.
    • Exclusive Re-Identification: The encrypted mapping table remains isolated and can only be decrypted by the authorized user.
  • Integrated Malware Analysis: Every uploaded document undergoes automated virus and malware scanning before processing and indexing.

4. Identity, Permissions & Access Control

  • Granular 3-Tier Permission Architecture (Least Privilege):
    • Tier 1 (Tenant Role): Strict role separation within the tenant (Administrator, Editor, User) with no implicit permissions on third-party data.
    • Tier 2 (Feature Capabilities): Modular assignment of platform features and module permissions.
    • Tier 3 (Entity-Level Whitelists): Explicit permission assignment for documents, knowledge spaces (Spaces), AI agents, and files, including virtual user groups.
  • Server-Enforced Multi-Factor Authentication (MFA / AAL2): Critical corporate resources and administrative interfaces enforce Authenticator Assurance Level 2 (AAL2 via TOTP).
  • Protection Against Side-Channel & Timing Attacks: Authentication tokens, CSRF tokens, and API signatures are validated using cryptographic constant-time operations.
  • Modern Session Management: Short-lived JWT access tokens with automated refresh token rotation and OAuth 2.1 with PKCE for browser extensions.

5. Network Security, API Hardening & DevSecOps

  • Intelligent Rate Limiting: Persistent, token-based rate limiting with SHA-256-hashed scopes to protect against DoS and brute-force attacks.
  • SSRF Protection & DNS Rebinding Filtering: Strict validation of outbound interfaces, including automatic blocking of private IP ranges (RFC 1918, IPv6 ULA) and cloud metadata endpoints.
  • Cryptographically Signed Webhooks: Replay protection through HMAC-SHA256 signatures with timestamps and nonce validation.
  • Automated Security Gates in CI/CD (Shift-Left DevSecOps):
    • Shift-Left Secret Protection & Pre-Commit Gates: Automated scanners cryptographically and heuristically prevent credentials, API keys, or service tokens from entering source repositories – directly at the developer level prior to each Git commit.
    • Continuous Source Code Analysis (SAST & Policy Linting): In-depth static analyses (including GitHub CodeQL and specialized security rulesets) detect taint flows, ReDoS risks, and injection vectors. Dedicated database linters verify the seamless enforcement of Row-Level Security (RLS) and secure function definitions before every release.
    • Behavioral Supply Chain Security (SCA): Advanced verification of third-party libraries for malicious code, typosquatting, and suspicious network activity during installation and build stages, well beyond reactive CVE lookups.
    • Dynamic Application Security Testing (DAST): Regular automated scans of staging and API infrastructure evaluating HTTP security headers (HSTS, CSP), CORS configurations, and TLS compliance (OWASP standards).
  • Audit-Proof Logging & Soft Deletes: Changes to core entities and security configurations are immutably logged. Multi-stage logical deletion concepts protect against accidental data loss.

6. Compliance, Data Residency & Certification Roadmap

  • 100% Data Residency & Processing in the European Union:
    • Primary Database, Authentication & Edge Functions (Supabase / AWS): Frankfurt am Main, Germany (eu-central-1).
    • Application & DLP Microservices (Google Cloud Run): Frankfurt am Main, Germany (europe-west3).
    • Document & File Storage (Google Cloud Storage): European Union (EU) multi-region.
    • Enterprise AI Inference & Embeddings (Google Gemini Enterprise): European Union (EU) multi-region.
  • GDPR Compliance & EU AI Act Readiness:
    • Consistent implementation of Privacy by Design and Privacy by Default (Art. 25 GDPR) as well as appropriate technical and organizational measures (Art. 32 GDPR).
    • Standardized Data Processing Agreement (DPA / AVV) including detailed technical and organizational measures (TOMs).
    • Automated workflows to fulfill data subject rights (access under Art. 15/20 GDPR and cascading deletion under Art. 17 GDPR).
  • Compliance for Professional Secret Carriers (Sec. 203 StGB, Sec. 62a StBerG, Sec. 43e BRAO & Sec. 50a WPO):

    Sylaxis is designed for legally compliant deployment in practices of tax advisors, certified public accountants, and law firms bound by professional confidentiality:

    • Assisting Person (Cooperating Third Party): Sylaxis acts as an assisting person within the meaning of Sec. 203(3) sentence 2 of the German Criminal Code (StGB) and relevant professional codes (Sec. 62a StBerG / Sec. 43e BRAO / Sec. 50a WPO).
    • Penal Confidentiality Obligation: All employees and vicarious agents with potential administrative access are formally bound to confidentiality and instructed on the criminal penalties under Sec. 203(4) StGB.
    • Zero-Training & EU Data Residency: Contractually guaranteed zero-training and data processing strictly within certified European Union data centers (including database & microservices in Frankfurt am Main as well as file storage & AI inference in the EU multi-region) safeguard client privilege at all times.
    • Dedicated Law Firm Addendum: In the customer dashboard, we provide a specialized “Agreement on the Protection of Professional Secrets (Sec. 203 StGB / Sec. 62a StBerG)” alongside the standard DPA.
  • Availability & Disaster Recovery:
    • Daily automated backups and Point-in-Time Recovery (PITR).
    • High resilience through geo-redundant storage within the EU.
  • Certifications of Underlying Cloud Infrastructure:

    The physical data centers and foundational cloud services of our partners are audited and certified according to top industry standards:

    ISO/IEC 27001ISO/IEC 27017ISO/IEC 27018SOC 1SOC 2 Type IISOC 3BSI C5TISAX
  • Sylaxis Security Governance & Certification Roadmap:

    Sylaxis develops and operates all software services following the established control objectives of ISO/IEC 27001, BSI IT-Grundschutz, and the OWASP Top 10 framework (Security & Privacy by Design).

    Compliance Roadmap: Formal company-level certifications (ISO/IEC 27001 and SOC 2 Type II) are on our strategic roadmap and will be audited as the company scales.

    Transparency & Vendor Audits: For security assessments and vendor reviews, we gladly provide enterprise customers upon request with our standardized security questionnaires (e.g., CAIQ / VSAQ) and our comprehensive TOM catalog (team@sylaxis.com).