What We Do Not Claim
SynapSync is not certified. No ISO 27001, no TISAX, no BSI baseline attestation. Any vendor of this size telling you otherwise should be able to show you the certificate.
Nor does this page claim that deploying our systems makes you compliant with anything. That comes from your own assessment, your documentation and your processes. What we describe is narrower and more verifiable: which architectural property makes which piece of evidence easier to produce.
GDPR: The Difference Between “May Not” and “Cannot”
A data processing agreement governs what a vendor may do with your data. It presumes the vendor has access in principle, and limits it contractually.
In an air-gapped deployment that access does not exist. Processing runs entirely on your hardware, there is no back-channel to us, and no telemetry is transmitted. The question moves from the contractual to the technical level — it is not assured, it is not constructible.
Where you still have to look: machine data is usually not personal data. Shift assignments, operator IDs and maintenance reports containing names may well be. Whether and how that applies to you belongs in your record of processing activities — we cannot decide it for you, and we do not.
EU AI Act: Classification Is the Operator’s
The EU AI Act attaches to the intended purpose, not to the vendor. Predictive maintenance on production equipment is as a rule not a high-risk use case. If the same detection is deployed as a safety component of a machine — such that a wrong judgement could endanger people — the classification shifts.
You make that assessment. What we supply for it:
- Technical documentation of the deployed model: training basis, signal classes, known limits.
- Traceability of the individual decision — which signal, which cycle and which correlation a detection rests on.
- Documented behaviour under uncertainty: where confidence is insufficient, the case is flagged for human review rather than guessed.
- Human oversight as a design principle: Henri supplies decision-relevant information. Switching actions and maintenance decisions stay with the operator’s staff.
NIS2: Supply Chain Is the Point
Among other things, NIS2 requires affected entities to manage supply chain risk and report security incidents. For you that means being able to justify why a supplier is acceptable.
A system without remote access is easier to justify than one with it. Not because we promise security, but because the usual routes are absent: there is no maintenance channel for an attacker to enter through, no cloud whose outage reaches you, and no telemetry whose flow you would have to explain.
The cost is worth naming honestly: updates require a physical or explicitly approved route into your environment. A cloud solution is more convenient. This one is more demonstrable.
What You Actually Receive
This page is not legal advice. It describes technical properties so that your own assessment reaches a conclusion faster — not so that it can be skipped.
Frequently Asked Questions
Is SynapSync ISO 27001 or TISAX certified?
No. We hold no certificate and claim none. What we deliver are architectural properties — on-premise processing, no back-channel, logged administrative access — and the documentation your own assessment can work from.
Do we need a data processing agreement with SynapSync?
That is your data protection officer’s call, not ours. The point is a different one: in an air-gapped deployment SynapSync processes no data during operation, because there is no access. A contract governs what a vendor may do. An architecture without a back-channel governs what it can do.
Does the system fall under the EU AI Act?
That depends on the use, not on the vendor. Predictive maintenance is as a rule not a high-risk use case; if the same technology is deployed as a safety component of a machine, that can change. The classification is made by the operator. We supply the technical documentation needed for it.
How does this help with NIS2?
Among other things, NIS2 requires supply chain risk to be managed. A supplier without remote access, without telemetry and without cloud dependency reduces exactly that attack surface — not because it is promised, but because the connection does not exist. You produce the evidence; we supply what it rests on.