Skip to main content
Sytance logo
Company

About Sytance Technologies

Sytance Technologies Limited is a product cybersecurity company. We build the Sytance platform and provide professional services for organisations responsible for connected and software-enabled products.

Last updated 13 September 2026

Company in brief

Sytance Technologies Limited (序衡科技有限公司) develops and operates Sytance. The company combines a product cybersecurity and compliance platform with specialist advisory, engineering, assessment, and documentation services.

Company introduction

Sytance Technologies Limited (序衡科技有限公司) is a technology company focused on product cybersecurity. The company develops and operates Sytance, a software-as-a-service platform for product cybersecurity and compliance work, and delivers related professional services.

Our work sits between product engineering, cybersecurity, quality, regulatory and compliance functions. We help these disciplines work from the same product context, preserve the reasoning behind security decisions, and maintain evidence as products and obligations change.

Sytance is the product and brand used for the platform. Sytance Technologies Limited is the company that develops, operates, and supports it.

Why we exist

Connected-product security is not a single assessment or document. It links product architecture and data flows to threats, risks, requirements, controls, verification, vulnerabilities, software components, evidence, and post-release decisions.

When this work is spread across documents, spreadsheets, ticketing systems, and specialist tools, the relationship between a decision and its evidence is easily lost. Our purpose is to make product cybersecurity work more systematic, reviewable, and maintainable without removing professional judgement.

Platform and professional services

The Sytance platform connects product context, architecture and data-flow analysis, threat and risk work, security requirements and controls, verification evidence, SBOM and vulnerability activities, and technical documentation in one traceable workspace.

AI-assisted workflows can analyse supplied context and prepare structured proposals or draft material. Users review those proposals before applying them, and accountable professionals remain responsible for approvals, risk acceptance, technical conclusions, and external submissions.

Professional services complement the platform when an organisation needs specialist advice, independent challenge, practical delivery capacity, or support for a defined programme, product, assessment, or release.

Our team

Our team brings together product security engineering, cybersecurity risk and compliance, security testing, software engineering, and technical documentation. This multidisciplinary model is important because a credible product-security decision must be technically sound, traceable to product evidence, and usable by the people responsible for engineering, quality, compliance, and management review.

We work with customer product owners, architects, developers, security specialists, quality and regulatory teams, assessors, and leadership. The role of our team is to make complex security work understandable and actionable while preserving the assumptions, evidence, and decision ownership needed for review.

Engagements are organised around a defined technical and business outcome, documented assumptions, appropriate specialist review, and clear ownership of actions and decisions. This keeps advice connected to the customer's product and operating context rather than reducing the work to a generic checklist.

Professional capabilities

  • Product security strategy and compliance planning, including work aligned to the EU Cyber Resilience Act, IEC 62443, medical-device cybersecurity expectations, and secure product development practices.
  • Product context, architecture and data-flow analysis, threat modelling, attack-path analysis, cybersecurity risk assessment, and security requirements.
  • Security architecture and control design, including traceability from identified risk to implementation and verification evidence.
  • Penetration testing, technical security assessment, vulnerability validation, and remediation support.
  • SBOM, open-source and supplier risk, vulnerability monitoring, coordinated disclosure, and post-market or post-release vulnerability handling.
  • Secure development lifecycle design, governance, review criteria, evidence models, technical documentation, and assessment preparation.
  • Role-based training, facilitated workshops, and working sessions that transfer methods into a customer's own engineering and governance processes.

How we work

  • Start with the real product — its intended use, architecture, data, interfaces, operating environment, users, and lifecycle — before selecting controls or producing documents.
  • Connect decisions to evidence so reviewers can understand what was considered, why a conclusion was reached, who approved it, and what must be revisited when the product changes.
  • Use automation and AI to reduce repetitive analysis and drafting, while keeping consequential decisions under human review.
  • Apply methods proportionately to product risk, maturity, regulatory context, and the purpose of the engagement rather than forcing every organisation into one template.
  • Design outputs to remain useful after an assessment or release, including for maintenance, vulnerability handling, change impact, and future assurance work.

Who we support

We support organisations that develop, manufacture, supply, operate, integrate, or maintain connected and software-enabled products. Typical work involves product manufacturers, software providers, engineering teams, and service organisations that need to establish or improve product-security evidence and decision-making.

The platform and services can be used for a new product, an existing product portfolio, a compliance programme, a defined security assessment, or the transition from document-based work to a connected operating model.

Sytance supports cybersecurity and compliance work; it does not itself certify a product, replace an independent conformity assessment, or transfer accountable decisions away from the customer.