Archetype C — Niche regulated enterprise
Syncanix for niche regulated enterprise
Maritime cybersecurity vendors, industrial-OT SOCs, and regulated identity platforms run a customer dashboard that is the product. Support is high-stakes — a missed alert is a vessel offline; a fumbled write is a regulator letter. They will not adopt an AI agent that lacks a per-tenant audit log, EU residency, or a credible single-tenant path. Syncanix ships the audit log and EU residency on day one, with a private-VPC path on Enterprise — so the security review opens with "yes, show me the packet."
Who it is
- EU-primary (Athens/Hamburg/Rotterdam/Tel Aviv/Oslo); 100–800 employees, $20M–$300M ARR; IMO 2021 / IACS / NIS2 / SOC 2 / ISO 27001 / HIPAA-regulated.
- The post-auth dashboard IS the product; public docs portal usually absent; chat lives inside the dashboard.
- SAML/SSO mandatory; single-tenant or per-customer-VPC common; air-gapped/private-cloud requested by ≥30% of pipeline.
- Buyer: Head of CS / VP Product, routed through a CISO + General Counsel; 3–6 month cycle; $100k+ ACV.
The pain
- High-stakes, low-volume support — per-seat AI bots are priced for SaaS volume, not SOC stakes.
- Audit log is the product — a bot that doesn’t stamp its actions onto the customer’s audit log is inadmissible.
- EU residency, on-prem, BYOK are non-negotiable RFP line items — US-only inference planes lose at security review.
- Write actions on critical infrastructure require identity-attributable governance or they’re a P1 waiting to happen.
How Syncanix solves it
- Audit log as a tier-one product surface — every write and tool call lands on an identity-attributable, tenant-scoped audit row (who, what, before/after) that survives offboarding.
- EU data residency on day one — all data pinned to the EU region, documented in the data-flow diagram.
- Private-VPC deployment path as an Enterprise add-on — single-tenant isolation for the security reviews that require it.
- BYOK + per-tenant KMS — on Enterprise the customer holds the key; Syncanix brokers the cipher, not the plaintext.
- Compliance packet ready to ship — SOC 2 Type I targeted Q3 2026, ISO 27001 targeted Q4 2026, OWASP LLM Top-10 documented; MSA/DPA/AI-addendum/SCCs/BAA templates on hand.
The wedge
- Per-tenant audit log + EU residency + a private-VPC Enterprise path — stated plainly, with the compliance calendar published on the trust page.
- The security packet is the opening of the conversation, not the close.
Pricing path
- Lands on the Enterprise tier — from $36K/yr on a custom MAEU contract, with BYOK, Private MCP, SSO/RBAC, EU residency, private-VPC option, named CSM.
- Pilot starts on Growth/Scale against the post-auth dashboard surface before the Enterprise contract.