doc /custody/overviewrev 2026.08.11status production

decision custody for autonomous systems.

syen comply creates cryptographically sealed, independently verifiable evidence of consequential automated decisions and actions.

rfc 8785 canonicalization·ed25519 signatures·rfc 3161 timestamps·customer-controlled keys

automated systems can generate logs, traces, and decision records. syen adds a separate custody layer so the integrity of a consequential record can be independently verified later.

§01 decision custody interactive

decision custody for automated systems.

capture a consequential decision, seal the record, export the evidence, and verify it independently. once a decision enters syen custody, later modification becomes detectable — verification does not depend on trusting the originating application, a syen dashboard, or a mutable audit log.

automated systemmakes a decision or takes an action
syen complycapture → canonicalize → sign → chain → timestamp
portable evidenceexport → verify independently → detect later modification
01the decisionnot yet in custody
decision idDEC-847291
systemautomated credit decision service
decisioncredit limit increase
outcomeAPPROVED
requested limit$25,000
approved limit$20,000
risk tierLOW
policy versioncredit-policy-v12
decision timestamp2026-08-11T16:42:18Z
demonstration data only
places the record into custody · signs and chains it

deploy syen comply

run syen inside your existing enterprise environment with customer-controlled cryptographic keys.

view syen in the okta integration network
the distinction
governance interprets. custody verifies.

governance systems can evaluate policy, risk, and system behavior. syen comply serves a different function: preserving cryptographically signed evidence whose integrity can be verified independently after capture.

no model is required to verify the evidence.

§02 how decision custody works

why the proof you just verified holds.

five cryptographic steps turn a decision record into evidence that can be checked without trusting syen. each is a public standard with public verification tooling.

01

canonicalize

the record serializes to one deterministic byte sequence. one byte changes and the digest changes.

rfc 8785 · sha-256
02

sign

the digest is signed with an ed25519 key held in your kms. syen never holds the private key.

ed25519 · customer key
03

chain

each record carries the digest of the one before it. rewrite a record and every record after it stops verifying.

per-tenant hash chain
04

timestamp

a trusted timestamp authority attests to when the record entered custody.

rfc 3161 · digicert tsa
05

verify

the exported proof verifies offline with public tooling. no syen service, dashboard, or model required.

portable · independent
§03 built for regulated automated decisions

financial services.

the primary application: consequential decisions made automatically, where the record has to hold up long after the decision was made.

financial services

automated credit, fraud, underwriting, payment, and agent-driven workflows can produce consequential decisions at machine speed.

syen comply preserves a sealed record of the decision context after capture, so later modification becomes detectable and the evidence can be independently verified.

§04 designed to remain independently verifiable

trust the math, not the vendor.

every capability below exists so the evidence stays verifiable outside the system that produced it.

customer-controlled keyssigning keys live in your kms. syen never holds the private key.
portable proof artifactseach proof exports as a self-contained signed json bundle.
independent verificationverifies offline with public tooling. no syen call required.
per-tenant cryptographic chainseach tenant gets a separate hash chain and key separation.
procurement
aws marketplacedeploy through your existing aws procurement process.deploy on aws
microsoft azure marketplacedeploy through your existing microsoft procurement process.deploy on azure
integration ecosystem
okta integration networksyen comply is available in the okta integration network.view integration
§05 broader applicability
autonomous infrastructure

syen can also preserve evidence for consequential agent actions and automated workloads running in regulated infrastructure.

explore autonomous infrastructure use cases →
§06 compliance
proof packages map tosr 26-2·nist ai rmfview all mappings →

the system made the decision.syen preserved the evidence.

also available in the okta integration network ↗