Platform Architecture

Microservices architecture built for scale. API-first design — every component is containerized, observable and independently deployable.

Home / Architecture

How It Works

🖥️
Admin UI (React SPA)
Full-featured web interface for all platform operations
Core API (FastAPI/Python)
Business logic, AI orchestration, auth, webhooks
🤖
AI Engine + Healing Engines
4 analysis modes + 7 healing engines
🧠
RAG Knowledge Base (pgvector)
Semantic search, session memory, auto-generated runbooks
🗄️
PostgreSQL + ClickHouse + Redis
Operational data, time-series logs, caching, vector DB
📡
Kafka + Filebeat Pipeline
High-throughput log ingestion → ClickHouse (30d retention)
🛡️
Security Monitoring (XDR)
FIM, vulnerability, compliance, MITRE, active response
🔧
Workers (1..N SSH agents)
Dynamic scaling, remote command execution

Live Pipeline

Real-time data flow from ingestion through enrichment to AI-powered action.

Servers Kafka ClickHouse Logs 🚨 Incident Detection Auto-alerts & anomaly detection Context Enricher RAG Search + Topology BFS 🤖 AI Analysis (Ollama/OpenAI) ✅ Action Log Throughput 12.4K events/sec Avg Analysis 12s -64% vs manual Knowledge Base 1.6K chunks indexed

Incident Auto-Analysis Pipeline

Fully automated incident lifecycle — from detection through 4-mode AI analysis.

🎯 Incident Detector ClickHouse anomalies 📡 Event Router Kafka event stream 🌐 API Create POST /incidents 📦 Redis Streams (CG+DLQ) XADD from detectors | XREADGROUP by consumer Q 🔁 Queue Consumer RPOP → INSERT pg 🗄️ PostgreSQL incidents table direct INSERT 🔍 Analysis Worker poll 30s → ai_analysis=NULL ⚡ Fast Analysis 🔍 Deep RCA 🛡️ Security 🤖 Autonomous Fix DETECTION · REDIS · PERSIST · ANALYZE — FULLY AUTOMATED Consumer poll: 5s Analysis poll: 30s

SYNOTI in Production

0
Background Services
auto-restart · Docker
0
Prometheus Exporters
real-time metrics
0%
Self-Heal Rate
~90% auto-recovered
0
Endpoints Benchmark
100 GB/day

What Teams Say

SYNOTI cut our MTTR from hours to under a minute for routine failures — the self-healing engine resolves most issues before my team even sees a ticket.
Operations Director
Financial Services
Air-gap readiness was the deciding factor. All 33 services run on our hardware with zero egress — exactly what our compliance team required.
Chief Information Security Officer
Government Sector
From Telegram ChatOps approvals to AI root-cause analysis, the platform fits how our SREs already work. Deployment took less than 15 minutes.
SRE Lead
Telecommunications

Common Questions

Python 3.13, FastAPI, PostgreSQL 16 + pgvector, ClickHouse, Kafka, Redis and Docker Compose — ~45K lines of code.
Yes — 33 containerized services, API-first, independently deployable and observable.
Validated at 400+ managed agents with sub-10ms query latency; distributed across hosts for larger fleets.
Air-Gap ReadyZero TelemetryWazuh 4.x XDRMITRE ATT&CK15 SOAR Actions230+ REST APIs5 RBAC RolesMTTR < 60s

How It Works

End-to-end pipeline diagrams from the SYNOTI engine.

Built for scale

Deploy SYNOTI on your infrastructure today — air-gapped, self-healing, AI-native.