Company

SYLVA Labs builds instruments for AI accountability.

We are a Singapore-headquartered company building enterprise AI governance for regulated industries — banking, insurance, healthcare and government — across Singapore and ASEAN first.

01Why we exist

The question that started the company

Every enterprise we worked with was deploying AI faster than it could account for it. The question that decided everything was the one a supervisor eventually asks: show me every AI system you run, and prove the controls around each. The organisations that can answer it will keep their licence to deploy. The ones that cannot will spend 2026 explaining gaps.

So we built one instrument that answers it. Read-only, it observes and proves — in your own tenant, on Azure. With the enforcement layer deployed, it also stops what you say it must — anywhere your agents run. The same discipline runs through both postures: full-estate discovery, honest evidence, and no invented numbers — in the product or on this website.

SYLVA Labs

  • FocusEnterprise AI governance
  • BuyersCIO · CISO · Head of AI · Risk
  • SectorsRegulated industries
  • RegionSingapore / ASEAN first

02How we work

Three principles, held strictly

Never fabricate

No invented statistics, customers, logos or case studies — on this site or in our products. Our reporting engine marks what is not connected rather than guessing. We hold ourselves to the same standard.

Never dilute read-only

The read-only guarantee is absolute. Enforcement lives in separate components you deploy and authorise explicitly. The two postures never blur — in architecture or in language.

Singapore first

A Singapore CISO should meet their own regulator and a date before they meet a foreign fine. Our evidence model is built around MAS and PDPC expectations first, then the frameworks Singapore firms face abroad.

03Scope

What we deliberately do not build

A company that claims everything is telling you it has decided nothing. These are the lines we hold, and they are architectural rather than aspirational.

Not a general GRC suite

We govern AI systems and the agents built on them. Enterprise risk registers, HR controls and physical security belong to tools that already do them well.

Not endpoint security

Laptops, mobile fleets and office networks are somebody else's job. We watch what your AI does, not what your staff do.

We never execute your actions

The Gatekeeper permits, denies or pauses. Agents act with their own credentials, issued by you. A vendor that cannot use what it does not hold cannot become your breach.

We never hold your data

Everything runs inside your boundary. Prompts, completions and evidence stay there. There is no vendor-side copy, so there is nothing of yours for us to lose.