Synlian — Quantum age applications for digital age supply chains

Security & governance

Engineered to international internet-banking security standards from day one.

Not a compliance checklist bolted on at the end — the controls below are how the platform works, and each one is held in place by automated tests.

ISO 20022 pain.001 / pain.002·UBL 2.5 invoicing·SWIFT MT940 statements·WebAuthn / FIDO2 passkeys·Double-entry accounting discipline

Identity

Authentication without passwords

Passkeys, not passwords

Sign-in uses WebAuthn passkeys with user verification required — phishing-resistant cryptographic credentials bound to the user’s own device. There is no password to steal, guess or reuse.

Step-up for money movement

Approving a payment requires a fresh 6-digit authenticator code on top of the session — a time-boxed authorisation bound to that person, that action and that specific voucher.

Signatures bound to documents

Client acceptances — offers, facility agreements — are passkey signatures bound to the exact document hash. What was signed is provable, byte for byte.

Sessions

Session security, assumed hostile

Hashed, rotated tokens

Refresh tokens are stored only as one-way hashes and rotated on every use. Session cookies are invisible to browser scripts; access tokens are never persisted on the device.

Automatic theft response

A replayed stolen token revokes the entire session family and alerts the account holder. Repeated failures lock the account and trigger an immediate alert.

Kill switch

Administrators see live sessions and can force-terminate any of them instantly — for staff and for client accounts alike.

Governance

Four eyes, enforced in software

Maker ≠ checker ≠ approver

Every governance gate — payments, offers, credit limits, risk models, offer letters — separates the person who prepares from the people who check and approve. Holding every permission still doesn’t let one person walk a decision through alone; the software refuses.

Thresholds you set

Larger amounts automatically require more approvers, at levels your own administrators configure. The requirement is frozen when the item is created — a mid-flight rule change never moves the goalposts.

Permissions, not job titles

Every screen and action sits behind a fine-grained permission key. Your administrator assembles keys into roles; what a person cannot do simply does not appear — no forbidden errors, no grey buttons.

Fails safe

A missing rate, rule or approval stops the action with a clear message naming what’s missing. The system never guesses with money.

Evidence

Append-only, regulator-ready

Every auth event on record

Logins, refreshes, lockouts, signatures, revocations — written to an append-only audit log that is never updated or deleted. A tamper-evident trail for any review.

Books that cannot be rewritten

The ledger is append-only; corrections are reversing entries. The full history of every cent stays available, permanently.

Decisions with their reasoning

AI-analyst proposals, human sign-offs, overrides and configuration changes all land on the record with before-and-after detail.

Isolation

One funder, one environment

Each funder's deployment is dedicated: separate services, separate databases, separate models, no shared network. Application-level permissioning is defence in depth inside your environment — not the boundary between you and anyone else.

Proven, not promised

Every control on this page is exercised by automated end-to-end tests against the real system — real database, real messaging, real bank-format files, no mocks. The suites assert the refusals as well as the approvals: a self-approved payment, a replayed token, an unbalanced posting each fail the build before they could ever reach a customer. Production hardening — TLS everywhere, secrets management, breached-password screening, anomaly detection — is a stated roadmap, not fine print.

Put your security team in the room.

We'll walk the controls live and leave you the evidence trail.

Request the security briefing