FAQ
Asked by people who read footnotes.
Straight answers, including where the limits are.
Does AI Pulse ever write to our environment?
Not in its read-only deployment. It runs with a read-only managed identity and zero write permissions — there is no write capability to grant, misconfigure or leave broad. This is the product's foundation and we never dilute it. If you need enforcement, that is a layer you deploy, with stops you explicitly authorise per agent.
Is the MAS AI Risk Management Guidelines regime already in force?
No. MAS consulted on the draft guidelines from 13 November 2025 to 31 January 2026. Final guidelines are expected in 2026 with a proposed 12-month transition period; once final, MAS will assess AI risk management at inspections and supervisory reviews. MAS has, however, already examined banks' AI model risk practices in a mid-2024 thematic review (published 5 December 2024), so supervision in this area is active.
Is this one product or two?
One. The same portal, registry and evidence model throughout. What varies is how much of it you deploy: read-only on Azure today, and an enforcement layer — inline guardrails, tool-intent interception and the Action Gatekeeper — that you add when you need the platform to stop an action rather than record it. Adding enforcement does not mean migrating to a different product or repeating procurement.
If it can enforce, is it still read-only?
In the read-only configuration, yes — and not as a setting. The enforcement components are separate services; where you have not deployed them, no write capability exists in the permission set to grant, scope down or leave broad. That is why the read-only guarantee survives on a product that is also capable of stopping things: you are not switching enforcement off, you are choosing not to install it.
Does it work in air-gapped environments?
Yes. With enforcement deployed, AI Pulse is cloud-agnostic and runs self-hosted, in sovereign clouds, and in fully disconnected environments. Evidence and the decision ledger stay in-environment; there is no external dependency.
Where does our data go?
Nowhere. AI Pulse deploys into your own Azure tenant as a managed application; data, telemetry and evidence remain there. With enforcement deployed it runs inside your environment, including air-gapped ones. We do not receive your asset data.
Does it hold credentials to our systems?
Never. The Action Gatekeeper permits, denies or pauses an action — it does not execute it. Agents act with their own scoped credentials, issued by you; AI Pulse never generates, stores or holds them. Approval is bound to the exact parameters approved, and every decision is written to the tamper-evident ledger.
What open-source components are inside, and what do they cost?
AI Pulse composes proven open source under free MIT and Apache-2.0 licences for the gateway, trace store, safety scanning and telemetry collection — $0, with no paid tier of any of them used. They are referenced from their upstream registries and pulled by your own infrastructure, never embedded or redistributed by us. The governing layers — the policy engine, the Action Gatekeeper, the remediation bridge and the application itself — are SYLVA's own build, and a component-by-component justification is available for your architecture review.
Does it integrate with our ITSM and SIEM?
Yes. Findings raise tickets in ServiceNow or Jira Service Management through maintained integrations. Your SIEM connects either way you prefer: Splunk natively via HTTP Event Collector, or any SIEM — Microsoft Sentinel included — by polling a token-secured export endpoint or receiving an HMAC-signed HTTPS push. Delivery tracks a watermark, so a restart never re-sends or skips a record, and every audit entry carries its verification hashes. Self-healing is limited to a short, pre-approved list of reversible actions; beyond that list the platform only raises, routes and notifies — a human always makes the call.
Which frameworks do you map to?
45 frameworks and standards, including MAS guidance and information papers, PDPC advisory guidelines, IMDA's Model AI Governance Frameworks, ISO/IEC 42001, NIST AI RMF and the EU AI Act. One evidence set answers many letters.
Do you have customer logos or case studies we can see?
We do not publish customer names, logos or testimonials on this site — and we will not invent them. What we put in front of you during evaluation is the product itself, run against your own estate, with the architecture and security documentation and the component-by-component justification pack shared under NDA. You will be judging what it does on your systems, not what it did on someone else's.
How does pricing work?
Per estate, scoped during evaluation against what you actually run — tenants, agents, frameworks and review calendar. Coverage and prerequisites are verified before any commercial conversation.