Deployment

One standard. Two ways to run it.

The VAID primitives and the guarantees they carry are identical no matter who operates the control plane. What changes between these options is operational: who runs it, and where your identities, policy and audit records live. This page is written so a security or infrastructure reviewer can self-qualify.

01

The two paths

In development – not generally available

SaaS

SYNTHERA operates the control plane. The intended default path – described here so you can plan, not as a claim about today.

  • Hosted authority – issuing and revoking VAIDs operated for you. "Hosted authority" is our name for the aggregate of the durable pieces below plus KMS-backed keys; it isn't a component you can point at today.
  • Managed enforcement – policy decisions applied at call time. Cross-process enforcement across a whole estate is not shipped; the federation router is in-process today.
  • Managed audit-of-record – the durable, hash-chained history, retained and operated for you. The audit seam is already open source in vaid; what's commercial is the durable ledger.

Best when you want the guarantees without operating the control plane yourself. Talk to us about timing rather than assuming you can buy it today.

Roadmap – not available today

Self-hosted / on-prem

You run the control plane inside your own environment. On the roadmap, not started – described here so you can plan, not as a claim about today.

  • Your environment – the control plane runs inside your VPC or on-prem.
  • For regulated / air-gapped / residency-constrained teams that can't send identity or audit data outside their boundary.
  • Same open primitives – the same VAID standard underneath, with a commercial license for the operated components.

We'd rather flag this as roadmap than imply a self-hosted control plane you can run today.

IDENTICAL

What doesn't change

The VAID primitives and the guarantees they carry – a signed action anyone holding the signer's public key can verify, capability scoping, lineage, a tamper-evident record. The format and the signing contract are the same in both; that's the point of an open standard. Verifying a VAID issued by another deployment additionally needs that deployment's key – Planned.

DIFFERENT

What does change

Who operates the control plane, and where your identities, policy and audit records physically live. In SaaS, SYNTHERA operates it; self-hosted (roadmap) keeps operation and data inside your boundary.

SYNTHERA is the trust layer for multi-agent systems: every agent gets a verifiable identity, scoped authority and a tamper-evident record, so software from different teams, vendors and frameworks can act on each other’s behalf without custom glue between every pair.

Find the deployment that fits your constraints.

Tell us your residency, air-gap or operational requirements and we'll walk through what's possible today and what's on the roadmap.

Talk through deployment