Blog
Benchmarks, design decisions and how-tos: building AI agents in Synsema, and deploying them with a permission manifest, sealed secrets and an audit trail. Every post is also Markdown: add .md to its URL.
The judge slot is a protocol, not a vendor. Since v0.6.27 a Laya checkpoint on disk — ModernBERT, Apache 2.0 — answers whether, choose and rate with no network, no secret and no cost per token, and the same block runs unchanged.
Since v0.6.27 the embedded local provider takes the name of a model already in your Ollama or Hugging Face cache — nothing is downloaded — and an architecture is a text file the compiled binary reads, so adding a model no longer waits for a release of ours.
For some workloads the interesting question is not which model is best, but whether the data is allowed to leave at all. A model inside the process answers that with no egress, no vendor in the trust chain and no bill per token — and the price it charges is in latency and model size.
The calibrated probability that decides what a person sees no longer has to come from an API. An open-source System One checkpoint on your own disk answers the same typed questions with no key, no network and no cost per token — and the same program runs against either one.
Routing, tagging, eligibility and moderation are the highest-volume AI work most products do, and the cheapest to get wrong. A System One model answers them with a calibrated probability — and the economics are not close.
Nitro Enclaves, confidential VMs, dstack, chain-anchored — four places to put the part of your product the operator must not read, and how to pick one without a six-week spike.
A confidential deployment nobody verifies is an ordinary deployment with extra cost. Here is the checklist a serious counterparty runs, what your side has to publish for it to pass, and the limits worth stating yourself before they ask.
A trusted execution environment hides your data from the operator. It does not stop your own code from leaking it, and it does not tell the client what is running inside. Synsema does both — information-flow labels and attestation are part of the language, not a library.
Half the work we hand to an LLM is not writing, it is deciding: route this, flag that, is this a refund request. A System One model answers those with a calibrated distribution, and a language that has both slots lets each model do the half it is good at.
A model that returns calibrated probabilities instead of text changes the operational questions, not just the code. What to wire, what to gate, what to audit, and what happens on the day the provider is down.
Every line inside the box costs more to write, more to change and more to verify — and each change invalidates the measurement your customers pinned. The split between the confidential core and the ordinary product is the highest-leverage decision in the design.
Jev is TypeSafe's System One model: it answers with typed, calibrated probabilities instead of text. In Synsema it is a language primitive — `require judge`, one block, one call, three verbs — with honest degradation when it is not there.
A walkthrough, from an empty file to a service whose client verifies the code before sending anything — labels on, an attested identity, and the same checks running in CI with the development driver.
Telling a model "never call external APIs" is a request. A manifest the runtime enforces is a guarantee. What changes when permission is syntax, and why security teams say yes to one and no to the other.
A walkthrough of the invoice-agent recipe: how the manifest, the spend ledger, the sealed signing key and the approval step fit together, and what the audit log looks like after the first payment.
Most agent secret leaks are not clever. The model was asked for the key and it had the key. Sealed secrets remove the second half of that sentence, and change what a security review has to check.
Engine, program, modules, templates and assets in a single sealed executable, with a capability ceiling baked in. Nothing to install on the target — deploy it FROM scratch, or hand it to someone as a file.
A Synsema app is a website with automatic HTTPS, an installable phone app with native push, and a desktop app in its own window with your icon — from one server-rendered program and one API module. No native toolkit, no second codebase, no store required.
MCP is JSON-RPC. In Synsema the whole server is a dispatcher task and one POST route. Tools are tasks with real bodies, secrets stay sealed, and untrusted input runs under a capability ceiling.
Terminal or browser, any OpenAI- or Anthropic-compatible model, and tools that cannot leave your repo by construction. Lampson is a coding agent written entirely in Synsema.
A lamp is a portable unit of capability. Its manifest declares what the code may touch, the Synsema runtime enforces it and records every check. Install one with lamp add, expose it to any agent with lamp mcp.
synsema init --pwa gives any Synsema site a manifest, a service worker, icons and Web Push. It installs on Android, iOS and desktop with a home-screen icon and full screen — nothing native, no store.
A gate that waits for a real person — in the terminal, or queued behind one-time links when the program runs as a server — and denies when nobody is there. An agent cannot fake an approval.
synsema build --serve --no-console --icon turns the same server-rendered app into a double-click desktop app — a .exe with your icon on Windows, a .app on macOS, a launcher folder on Linux. The browser the user already has is the window, and the process quits when the last one closes. No Tauri, no webview, no second codebase.
cron_every takes an interval or a five-field cron expression and runs a task on its own thread, next to your routes. No crontab, no worker fleet, no message broker — and a human gate when a job needs one.
Synsema's built-in server issues and renews Let's Encrypt certificates itself. One flag turns the file you run in dev into a production HTTPS site, with HTTP/2, HSTS and www → apex.
A Synsema API is discovered by an agent in 1.37 ms, ahead of Go and Node — and the discovery documents are generated, not written.
Top-tier throughput plus capability security built into the language itself — why Synsema is the best fit for AI-agent backends and any service that handles untrusted input.