Syntryx Core

Institutional document · Ed. 2026 · EN

It comes in asserted. It goes out checkable by someone who does not trust us.

Software is today's form, not the definition: data model, engine, interface and tests. What is on the register is what exists.

Base
Delaware, United States
On the register
2 brands + one line with no public brand
Counted
265 requirements modelled in the open demo · 668 tests in the Atalaya repository

contact@syntryxcore.com

§ 01

What this house is

265requirements Clauses, Annex A controls, articles and measures modelled on the register today

Source: Salvik's demonstration organisation, § 02. Measured in the open demo; it does not come from clients.

Syntryx Core takes matters that are asserted and cannot be shown — a standard, a mailbox, an exposed surface — and returns them in a state where a third party can check them without trusting us. That is the operation. The sector is not part of the definition.

Today that operation is embodied in software: data model, engine, interface and tests. That is how the house builds in 2026, not what the house is. The catalogue is not closed, and § 04 states what that costs.

The audit and consulting practice —the one that reviews management systems and signs reports— is a separate activity, outside this house. Whoever builds a tool does not audit the same scope with it.

Admission test

In
It is asserted and cannot be shown
Out
An artefact a third party checks without trusting the house
Not admitted
What is already provable without us, and what cannot leave in that state

Register entry

Domains
syntryxcore.com · syntryxcore.es
Jurisdiction
Delaware, United States
What it does not do
It does not audit or certify: that is a separate practice
Third-party requests
None: typefaces served from this domain
Status of each brand
Declared wherever each brand keeps it current — not here
§ 02

What exists today

Entry 01

Salvik

Compliance management platform native to the European and Spanish regulatory frame. Its axis is the unified control model: implement once, comply many times. Every cross-mapping carries a confidence level, a justification and a citation, so the mapping can be audited instead of believed.

Asserted
“We comply with four frameworks at once.”
Leaves as
Requirement served or not, with confidence, justification and citation
Frameworks
ISO/IEC 27001:2022 · ISO/IEC 42001:2023 · NIS2 · ENS
Model
Unified control with quantified cross-mapping
Trace
Confidence, justification and citation per mapping
Stack
Next.js · React · TypeScript · PostgreSQL/Supabase

Measured in the open demo

4frameworks Seeded in the data model

265requirements Clauses, Annex A controls, articles and measures from 4 frameworks

85% Of the 26 unified controls serve two or more frameworks

12/15 Of the 15 obligations from arts. 20, 21 and 23 of NIS2 modelled in the demonstration organisation, served by ISO 27001 + ENS

Source: Salvik's demonstration organisation. It does not come from clients.

Which frameworks each demo control serves

12 bands · 26 controls

The 26 unified controls of Salvik's demonstration organisation, grouped into 12 bands. Each cell says whether the controls in that band serve requirements of that framework in this data set. It says nothing about the scope of the standard. Rows and columns are ordered by variation: the three bands that break the pattern head the table and the two columns with no absence at all sit on the right.
Control band ISO/IEC
42001
NIS2 ISO/IEC
27001
ENS
Risk management Serves Serves Serves Serves
AI governance Serves Does not serve Serves Serves
Physical security Does not serve Does not serve Serves Serves
Governance & policy Does not serve Serves Serves Serves
Access control Does not serve Serves Serves Serves
Security operations Does not serve Serves Serves Serves
Cryptography Does not serve Serves Serves Serves
Incident response Does not serve Serves Serves Serves
Continuity Does not serve Serves Serves Serves
People Does not serve Serves Serves Serves
Third parties Does not serve Serves Serves Serves
Development Does not serve Serves Serves Serves

The order is not alphabetical: the three bands that break the pattern — risk, AI governance and physical security — head the table, and the 42001 column sits against the labels so its shape can be read: two served cells and a block of ten absences. The 27001 and ENS columns are at 100% in this set and therefore sit on the right: they distinguish nothing.

An absence describes this set of controls, not the scope of the standard. ISO/IEC 42001 does cover governance (clause 5.2), people (A.3), third parties (A.10) and lifecycle (A.6): what the column says is that the demonstration organisation holds only 8 AI controls, and 4 of them cross no other framework.

The grid counts bands, not controls: each band groups several of the 26 unified controls, so the 85% in the figures column is not what you read here.

Controls in this band serve this framework None of them serves it in this set

Source: Salvik's demonstration organisation — 4 frameworks, 265 requirements, 26 unified controls grouped into 12 bands. Measured in the open demo; it does not come from clients.

Entry 02

Atalaya

Multi-vector email analysis engine: phishing, quishing (QR code) and BEC. It ingests .eml and .msg files and applies local rules over headers, domains, URLs, attachments and body content. External enrichment and AI analysis are optional, never mandatory: the engine has to be able to work without leaving the network it is deployed in.

Asserted
“This message is safe.”
Leaves as
A 0–100 score and a P1–P4 class, with the evidence that sustains them
Vectors
Phishing · Quishing (QR) · BEC
Input
.eml · .msg
Local rules
Headers · domains · URLs · attachments · content
Enrichment (optional)
VirusTotal · urlscan.io · EmailRep · AbuseIPDB
Output
Markdown and JSON report with findings and evidence
Stack
Python async · Docker · FastAPI

668tests Automated tests in the engine

0–100 Scoring range per message

P1–P4 Classification aligned to SOC prioritisation

3vectors Phishing, quishing and BEC in a single pass

Source: repository test suite, counted on 25 Aug 2026. It does not come from clients.

Entry 03 · —

External exposure

The house also builds external attack surface management (EASM) tooling: the inventory of what an organisation exposes to the internet without knowing — domains, subdomains, published services, leaked credentials, brand impersonation. It exists and is used in the house's own work, but it has no commercial name, so this entry stays open instead of being filled with one.

Passive reconnaissance · Public sources · No active scanning · No client deployments

Empty-field entry

Asserted
“We are not exposed.”
Leaves as
Inventory with a public source per finding. No published scale yet — that is why the entry stays open.
Commercial name
No public brand
Method
Passive OSINT over public sources
Use
The house's own work

This entry carries no figures: there is nothing measured to publish yet.

§ 03

How the house decides

  1. 01

    Admitted by criterion, not by sector.

    A compliance platform, an email engine and exposure tooling sit in the same house because they pass the same test, not because they share a market. If the answer to a problem is already checkable without us, the house adds nothing and does not take it. The cost is that this page cannot tell you which industry the house works in; it tells you which problem the house takes.

  2. 02

    Model before code.

    The data model comes before the interface; if the domain is not properly described, the screen merely hides the error.

  3. 03

    Every claim carries its evidence.

    A figure without a source is not published: not in the product, not in a report, not on this page.

  4. 04

    This page declares no brand's commercial status.

    A stamp written here ages the moment the product changes, and is contradicted one click away. Price, availability and terms are declared wherever each brand keeps them current, not here. The cost of that decision is that this page is no use for finding out whether something can be bought today, and it promises no place where you could.

  5. 05

    Not one third-party request.

    The two typefaces in this document are served from this same domain instead of from a CDN. It costs 88 KB of our own bandwidth and forces us to convert and version the files by hand every time they change; in exchange, the IP address of whoever reads this page reaches nobody else.

§ 05

Separation

Building a tool and auditing with it are two different activities, and this house only does the first. Syntryx Core builds. It does not audit, does not certify and issues no opinion on any management system.

The house builds; the practice audits. Never the other way round on the same scope.

Separation diagram

Syntryx Core builds the tool
Audit practice separate entity

Deliberate separation

§ 06

Single channel

contact@syntryxcore.com

No forms. No cookies, no analytics and no third-party requests. The only thing stored is your language, in your own browser.