Saphan

Enterprise — your machines, your record, your auditor’s evidence.

Saphan Studio runs where your code already lives and answers the questions your auditors already ask. This page says what that means in practice — and marks, honestly, what is shipped and what is still on the roadmap.

The enterprise position

01

Your machines, your record

The control plane and the runners are infrastructure you own or rent; the record lives in a PostgreSQL store you control, and its signed evidence in a CouchDB document database; the product opens no listening port on a runner. In Enterprise, identity stays on your infrastructure too: run saphan-oauth locally or connect any local IdP through the issuer trust list. Mobile notification signalling carries only an opaque gateId and badge count — never record content or a stream slug.

02

Three postures, differing by features — never by scale caps

Solo runs everything local. Team uses the Saphan-operated saphan-oauth SaaS for a group of humans. Enterprise keeps identity local — either customer-run saphan-oauth or any customer IdP behind a human-gated trust list. Team and Enterprise also support the data-free mobile notification signal; the application retrieves content from the customer gateway only after authentication. No tier meters your agents: you pay per human, and the fleet is workload.

03

Identity is real

Humans and agents act under a registry with delegated, time-bounded, scoped authority. Nothing gains permission by the passage of time, and retiring an actor takes effect immediately, regardless of unexpired grants. Access to the management surface is standard OAuth 2.1 / OIDC — customer-run saphan-oauth or your own local IdP — and fail-closed: an identity without an explicit grant reads zero rows.

04

Audit export, today

The record renders to Markdown, CSV, PDF, and HTML, including the cost lanes; the ledger exports as line-delimited JSON; operational metrics are a Prometheus scrape target — GET /metrics on the serving daemon: runs by status and backend, gate decisions by gate and decision, refusals by class. Refusals are a first-class metric, because on this architecture a refusal is a security signal, not noise; label values are class names only, never stream names or actors. Every dashboard, report, and export is a projection of the same record — there is no privileged screen, and losing an export invalidates nothing. SIEM connectors and signed audit bundles are on the roadmap; this page will say “shipped” when they ship, not one release before.

05

Compliance: the evidence, not the certificate

Standards certify your organization’s management system, not a vendor’s product. Saphan Studio produces, as a by-product of normal operation, the evidence your auditors ask for — designed to map onto the controls they already check, from ISO 27001 to the EU AI Act. The full mapping is its own brief.

Read the compliance brief →

06

Standard, easy installation

Containers or standalone — your choice. The control plane you host runs as ordinary services — console, API, authorization — on infrastructure your operations team already knows how to run, as containers or as standalone processes. Machines that do the work receive their payload automatically once the owner admits them to the fleet, with checksums verified on the receiving machine before anything lands. An air-gapped path stays first-class.

07

Patent pending

The core of Saphan Studio — approval that cannot exist without evidence, on a record a third party can verify — is the subject of a U.S. patent application. We describe it publicly the way this site does: by what it guarantees, not by how it is built.

More of Saphan Studio

Design partner inquiries

Contact us — [email protected]