The foundation

SYNTHERA

part of SYNTHERA

SYNTHERA is the trust and coordination foundation for multi-agent systems. It operates the open VAID standard at enterprise scale – one identity, one policy engine, one audit-of-record, rather than one of each per framework. Policy is enforced today on the root agent it provisions.

What it isTrust & coordination foundation
Built withRust core · one canonical source of truth
Identity proven acrossADK · OpenAI adapters
Policy enforced onThe provisioned root agent
StagePre-pilot · runs live on Cloud Run
01

The outcome

Before

Every team building with agents writes its own enforcement, audit and policy logic – once per framework, once per cloud. Rules drift between systems, logs don't reconcile, and nothing is verifiable end to end.

After

One deterministic policy engine and one audit-of-record instead of one of each per framework. Rules are authored once, evaluated on every request against the agent SYNTHERA provisions, and the record is tamper-evident.

SYNTHERA is what running the VAID standard at enterprise scale looks like – the single foundation every tenant, and every agent you build, sits on.

02

How it works

SYNTHERA is infrastructure, not a library you bolt on. VAID is the open identity primitive underneath; the foundation adds the four services every agent and every system above it consumes – and never reimplements.

FOUNDATION SERVICE 01

Policy

A deterministic, sandboxed evaluation engine – repeatable, fast, with an enforced instruction budget. Rules are authored off the hot path and evaluated on it against one shared logic. A verdict that blocks is live: the deployed substrate loads its rules at boot, evaluates every request against them, and a refusal names the rule that produced it. The default verdict for a request no rule matches remains allow.

deterministic · sandboxed · deny is live · authored elsewhere
FOUNDATION SERVICE 02

Capabilities

Authority is granted as bounded, scoped capabilities. An agent can do exactly what its capability set allows and nothing more – least authority by construction.

scoped grants · least authority
FOUNDATION SERVICE 03

Audit

A tamper-evident event log. Every action is recorded to one audit-of-record that no party can quietly rewrite after the fact.

tamper-evident · subscribe + project
FOUNDATION SERVICE 04

Federation

Coordination over a single, well-defined surface, so systems coordinate through SYNTHERA rather than bespoke glue. In progress: the router is in-process today – it reports its own readiness as Degraded – and cross-process transport between independent systems is not shipped.

uniform transport · one surface · in-process today

What a customer gets beyond the open standard

Anyone can adopt VAID, and anyone holding the signer's public key can verify its signed actions without lock-in – that's the point of an open standard. SYNTHERA is the infrastructure to operate it at scale, and it's the commercial product. It is in development, not generally available; the three below describe the intended offering, not what you can buy today.

Hosted authority

The issuing and revoking authority for VAIDs, operated for you – so identities can be minted, delegated and cut off centrally. It is our name for the aggregate of KMS-backed keys, durable audit and durable revocation, not a single component that exists today.

Enforcement mesh

Policy decisions applied at call time on the hot path, without each service wiring its own enforcement. Applying this across a whole estate needs the cross-process transport that is not yet shipped.

Audit-of-record

A durable, hash-chained history of what every agent did, and under whose authority. The ledger itself is real and its tamper-evidence is proven by attack rather than asserted: mutate a written row directly in the database and recomputation catches it, names the sequence number and exits non-zero. The audit seam is open source in vaid. What is commercial — and what we do not operate for anyone today — is retention: the ledger kept, run and exported on your behalf.

Architectural rules
R1 – The core is canonical. Systems above it subscribe and project from it. They never duplicate its state.
R2 – Enforced on the hot path, authored off it. The core evaluates; authoring happens elsewhere.
R3 – Primitives are consumed, never reimplemented. One identity model, one audit log, one policy engine.
03

Proof

Live today The foundation runs live on Cloud Run, and identity conformance has been demonstrated framework-agnostic across ADK and OpenAI adapters – the same VAID identity and attenuated delegation for all of them, proven by a dated conformance run. That run proves identity; it did not exercise policy. Policy is proven separately, and today on the root agent SYNTHERA provisions: the deployed substrate loads its rules at boot, evaluates every request against them, and a refusal names the rule. One shared policy engine and audit-of-record across every layer above that root is the foundation's design, not a claim we make as live yet.

You don't rip anything out

SYNTHERA sits above the frameworks and clouds you already run. It unifies them; it doesn't replace them.

Fig.02 · Composable, not a rip-and-replace
The unifying layer

SYNTHERA + VAID – one verifiable identity, one policy engine, one audit-of-record, rather than one of each per framework below.

One layer, not one per framework
Google ADK
LangChain
OpenAI
Your cloud provider

Keep the frameworks and clouds you already run. SYNTHERA sits above them – today it enforces policy on the root agent it provisions.

SYNTHERA is the trust layer for multi-agent systems: every agent gets a verifiable identity, scoped authority and a tamper-evident record, so software from different teams, vendors and frameworks can act on each other’s behalf without custom glue between every pair.

Talk to us about SYNTHERA.

For teams putting agents into production who already feel the cost of making them work together safely.

Talk to us about SYNTHERA