Core Principle
Capabilities define what apps CAN access. Consent defines what users ALLOW. Data access requires BOTH.
Capability Tiers
Synheart Core defines three capability tiers:1. Core (External Apps)
Available To:- Third-party applications
- External developers
- Public SDK users
- Basic HSI axes and indices
- Standard time windows (30s, 5m, 1h, 24h)
- Limited embedding access (normalized only)
- Standard cloud ingestion
- Basic interpretation modules (if enabled)
- Derived biosignals only (no raw signals)
- Standard frequency windows (no high-frequency streams)
- Derived metrics only (no fusion internals)
- Standard endpoints (no research-specific APIs)
2. Extended (Synheart Apps)
Available To:- Syni Life
- SWIP
- Pulse Focus
- Other Synheart-owned applications
- Full HSI axes and indices
- Full 64D state embeddings
- Higher-frequency updates
- Advanced app context
- Extended behavior metrics
- Extended cloud endpoints
- Advanced interpretation modules
- Derived biosignals only (no raw signal streams)
- Derived metrics (no internal fusion vectors)
- Extended endpoints (no research-specific APIs)
3. Research (Internal Research)
Available To:- Synheart Research team
- Authorized research partners
- Internal tooling and analytics
- Full HSI access
- Raw signal streams (with consent)
- Internal fusion vectors
- Event-level behavior data
- Full app context (unhashed)
- Research cloud endpoints
- Unrestricted time windows
- All access requires explicit user consent
- All access respects privacy boundaries and data protection policies
Module-Level Capabilities
Each module has tier-specific access levels:Wear Module
| Tier | Signals | Frequency | Format |
|---|---|---|---|
| Core | HR, HRV, sleep stages | 1-minute windows | Aggregates only |
| Extended | HR, HRV, sleep, motion | 30-second windows | Full derived signals |
| Research | Full biosignals | Real-time streams | Raw + derived |
Phone Module
| Tier | Context | Granularity | Privacy |
|---|---|---|---|
| Core | Screen state, basic motion | Coarse | Hashed app IDs |
| Extended | Screen, motion, app categories | Medium | App categories |
| Research | Full context, app names | Fine | Full context |
Behavior Module
| Tier | Metrics | Resolution | Data |
|---|---|---|---|
| Core | Basic patterns | Aggregates | Counts only |
| Extended | Extended patterns | Windowed | Timing patterns |
| Research | Full event stream | Event-level | All interactions |
HSI Runtime
| Tier | Outputs | Embeddings | Internals |
|---|---|---|---|
| Core | Basic axes | Normalized 64D | No fusion state |
| Extended | Full axes | Full 64D | No fusion state |
| Research | Full axes | Full 64D + fusion | Full fusion vectors |
Cloud Connector
| Tier | Endpoints | Frequency | Batch Size |
|---|---|---|---|
| Core | /v1/ingest/hsi | Standard | 10 snapshots |
| Extended | /v1/ingest/hsi | Higher | 50 snapshots |
| Research | /v1/ingest/hsi-research | Unlimited | 200 snapshots |
Capability Enforcement
1. Capability Tokens
Apps receive a capability token from the Synheart Platform during registration. Token Structure (JWT):- SDK validates token signature on initialization
- SDK caches capabilities locally
- SDK checks capabilities before each module operation
- Expired tokens require re-authentication
2. Runtime Enforcement
Each module checks capabilities before returning data:- Module initialization
- Data collection
- HSI computation
- Cloud upload
- API responses
3. Server-Side Validation
Synheart Platform validates capabilities for cloud operations:Capability Upgrades
Developer Applications
External developers start with Core capabilities. To request Extended capabilities:- Apply via Synheart Platform console
- Provide use case justification
- Undergo security review
- Sign extended data usage agreement
- Established developer account
- Clear product use case
- Privacy & security review
- User benefit justification
- Research tier not available to external developers
- Raw biosignals not available outside Synheart
Synheart Internal Apps
Internal apps (Syni Life, SWIP) automatically receive Extended capabilities. Process:- App registered in Synheart Platform
- Organization validation
- Extended capability token issued
- Regular security audits
Capability-Consent Interaction
Capabilities and consent work together:Example Scenarios
Scenario 1: External App, Full Consent- App capability: Core
- User consent: All modules granted
- Result: App gets Core-level HSI (basic axes)
- App capability: Extended
- User consent: All modules granted
- Result: App gets Extended-level HSI (full embeddings)
- App capability: Core
- User consent: Biosignals denied, behavior granted
- Result: App gets Core HSI with
affectaxes =null
- App capability: Research
- User consent: All modules denied
- Result: No data (consent required regardless of capability)
Capability Auditing
SDK Logging
SDK logs capability checks:Platform Analytics
Synheart Platform tracks capability usage:- Endpoint access patterns
- Capability tier distribution
- Upgrade requests
- Violations and errors
Security Considerations
Tampering Prevention
SDK Protection:- Capability tokens signed by Synheart Platform
- Code obfuscation (release builds)
- Runtime integrity checks
- Certificate pinning
- Token replay: Prevented by expiry
- Token forgery: Prevented by signature verification
- Module bypass: Prevented by enforcement at multiple layers
- Man-in-the-middle: Prevented by TLS + cert pinning
Violation Handling
If capability violation detected:- SDK logs error
- Operation denied
- Error reported to Synheart Platform
- Repeated violations → token revoked
API Reference
Check Capabilities
Capability Events
Testing
Mock Capabilities
For testing, override capabilities:Capability Test Matrix
| Test Case | Capability | Consent | Expected Result |
|---|---|---|---|
| Basic access | Core | Granted | Basic HSI axes |
| No consent | Core | Denied | All axes = null |
| Extended access | Extended | Granted | Full HSI + embeddings |
| Downgrade | Core | Granted | Core HSI (not Extended) |
| Research access | Research | Granted | Full HSI + fusion |
Migration Guide
From Core to Extended
When upgrading from Core to Extended:- Request upgrade via Synheart Platform console
- Update SDK to handle Extended data:
- Test thoroughly with Extended data
- Update privacy policy to reflect Extended data access
- Deploy with new capability token
Related Documentation
- Architecture - Module system and HSI Runtime
- HSV Specification - State representation
- Consent System - User permission model
- Cloud Protocol - Cloud upload specification
Last Updated: 2025-12-25 Version: 1.0.0 Author: Israel Goytom