Product family

Nineteen products, two platform tools.

The Synthology portfolio covers the imaging-stack lifecycle end-to-end: a tiered Image Orchestration line — three router options plus the full platform — alongside vendor-neutral archiving, de-identification, structured reporting, migration, whole-slide pathology, encounter workflows, the SynthIQ DICOM load balancer, the SynthCloudConnect result relay, the Device Registry DICOM device inventory, SynthInSight fleet analytics, and the SynthConstellation fleet console — sixteen products spanning the §520(o)(1)(D) non-device line. Plus SynthQMS, SynthVault and SynthInSight, the general-purpose business software that runs underneath.

DICOM routing & imaging workflow

Image Orchestration

The day-to-day imaging fleet — one capability set delivered across purpose-built products rather than one overloaded router. The Router family scales from no-frills streaming (Essential Router) to durable store-and-forward with transforms and load-failover (Core Router) to the full platform (XyDromatics Router), with Core MWL serving a Modality Worklist from HL7 orders. Around them sit the specialists — SR Engine for structured reporting, the Pathology Engine for whole-slide ingest, the Encounter Engine for POCUS-style encounter workflows, and SynthCloudConnect for cross-site image exchange. And above the fleet sit SynthIQ, our vendor-neutral DICOM load balancer, and SynthConstellation, the single-pane fleet console. They share architecture and underlying libraries, and ship as separate executables so a regulatory-class boundary is also a code boundary.

Compare all tiers & specialists in one matrix →

XyDromatics™ Router

Non-Device · §520(o)(1)(D)

DICOM routing platform.

Ingest from any modality, route by rules, transform tags, anonymize, prefetch, hold-and-release. The flagship workflow orchestrator — both the operating-control plane for an imaging department and the integration hub between modality, EMR, PACS, VNA, and reporting.

Learn more about Router →

Capabilities

  • C-STORE SCP + STOW-RS endpoints
  • Rule-driven routing with per-rule destinations
  • Tag transformation, anonymization, pixel redaction
  • Hold queue + manual release for sensitive studies
  • Q/R prefetch + scheduled forwarding
  • HL7 ingestion + worklist generation

XyDromatics™ Essential Router

Non-Device · §520(o)(1)(D)

Streaming DICOM router — entry / OEM tier.

The leanest member of the Router family: real-time DICOM streaming — receive, match priority routing rules, and multiplex-fan-out to destinations, with no store-and-forward. Lowest latency, smallest footprint — built to embed as an OEM routing layer, or to front a department that needs pure, fast C-STORE routing and nothing else.

Learn more about Essential Router →

Capabilities

  • C-STORE SCP receive → priority routing rules → multiplex SCU fan-out
  • Real-time streaming — no disk buffering, lowest latency
  • DICOM-TLS / mutual-TLS with certificate pinning
  • LDAP directory auth + RBAC / custom roles
  • Remote support & telemetry via SynthGateway
  • Windows MSI + Linux tarball

XyDromatics™ Core Router

Non-Device · §520(o)(1)(D)

Store-and-forward DICOM router.

The mid-tier of the Router family: a full store-and-forward DICOM router (DICOM-only). Each received instance is sealed to a durable encrypted spool, matched against priority routing rules, and forwarded to DIMSE or DICOMweb destinations with restart-surviving retry and dead-letter — plus per-destination transcode, de-identification, load-failover, a manual hold queue, and a PHI-free analytics window.

Learn more about Core Router →

Capabilities

  • Durable store-and-forward — seal-then-ack, restart-surviving retry, dead-letter
  • Priority routing rules with per-destination transforms on a clone
  • De-identification, burned-in-pixel redaction, tag coercion, transfer-syntax transcode
  • Load-failover — per-destination circuit breaker + cold-standby fallback chain
  • Manual-review hold queue + outbound DICOMweb (STOW-RS) delivery
  • PHI-free 7-day analytics · Windows MSI + Linux tarball

XyDromatics™ Core MWL

Non-Device · §520(o)(1)(D)

Modality Worklist from HL7 orders.

The Modality Worklist member of the Router family. An HL7 v2 MLLP listener ingests orders (ORM / SIU / ADT) into an encrypted order store, and a DICOM Modality Worklist (MWL) C-FIND SCP serves those orders back to imaging devices as a worklist. Order-in to worklist-out — the HL7/MWL slice, extracted from the flagship so the routers stay pure-DICOM.

Learn more about Core MWL →

Capabilities

  • HL7 v2 MLLP order ingest (ORM / SIU / ADT)
  • SQLCipher-encrypted order store
  • DICOM Modality Worklist (MWL) C-FIND SCP + C-ECHO
  • Operator-configured listeners with optional TLS / mTLS + source access control
  • Hot-bind configuration — add a listener with no restart
  • Windows MSI + Linux tarball

XyDromatics™ SR Engine

Non-Device · §520(o)(1)(D)

Structured-report ingest + forwarding.

A standalone licensed subset of the Router focused on SR (Structured Report) DICOM objects. Ingests SR from modalities, applies tag transformations, forwards to PACS/VNA + reporting platforms.

Learn more about SR Engine →

Capabilities

  • SR DICOM SOP class support
  • SR-specific tag transformations
  • Forward to PACS/VNA + report distribution
  • Standalone licensable SKU

XyDromatics™ Pathology Engine

Non-Device · §520(o)(1)(D)

Whole-slide imaging ingest sidecar.

WSI conversion sidecar for the archive family. Watches an intake folder, converts native pathology formats (SVS, NDPI, MRXS) to DICOM Supplement 145 WSI, and forwards via STOW-RS to your VNA. The only Windows-only product in the family (OpenSlideNET dependency).

Learn more about Pathology Engine (IPE) →

Capabilities

  • Native pathology format conversion (SVS, NDPI, MRXS)
  • DICOM Supplement 145 WSI output
  • STOW-RS forwarding to VNA
  • Watch-folder ingest pattern
  • HIPAA mode (license feature)

XyDromatics™ Encounter Engine

Non-Device · §520(o)(1)(D)

POCUS-style encounter workflow.

Encounter-driven imaging workflow with mandatory human verification gate. Receives DICOM, matches against an HL7 ADT feed, blocks on human verification, then forwards enriched studies to PACS/VNA. Closes the encounter loop with HL7 ORM^O01 / FHIR ServiceRequest back to the EMR.

Learn more about Encounter Engine →

Capabilities

  • DICOM ingest + HL7 ADT matching
  • Mandatory human-verification gate
  • Forward to PACS/VNA after verification
  • HL7 ORM^O01 / FHIR ServiceRequest emission
  • POCUS-style encounter UX

SynthIQ™

Non-Device · §520(o)(1)(D) Patent Pending

Vendor-neutral DICOM load balancer.

Drop-in replacement for F5, NetScaler, or HAProxy in front of any PACS or DICOM Router pool. Routes by Study Instance UID, not TCP 5-tuple — keeps every clinical study together on one backend across associations, follow-up imaging days later, and SynthIQ restarts. Works with any DICOM-conformant backend (Synthology fleet, vendor PACS, research VNAs, cloud-native endpoints).

Learn more about SynthIQ →

Capabilities

  • Persistent SUID-keyed study affinity routing
  • Three-tier waterfall: persistent affinity → least-busy → fallback
  • Health-aware backend selection (5s heartbeat polling)
  • Persistent affinity cache (SQLite, PostgreSQL, or SQL Server)
  • Admin SPA + JSON APIs for operators — pool/node, role, and settings management
  • Vendor-neutral by design (heterogeneous pools supported)
US Patent Applications
64/074,191 — Patent Pending
64/081,343 — Patent Pending

SynthCloudConnect™

Non-Device · §520(o)(1)(D)

Cross-site DICOM result relay.

Bridges AI-vendor result delivery into firewall-isolated on-prem Router fleets. The AI vendor C-STOREs results to a SynthCloudConnect endpoint; the on-prem Router pulls them down over an existing outbound-initiated mTLS WebSocket. No inbound firewall holes; no Synthology-to-customer initiated traffic. Generally available — self-hosted or hosted multi-tenant.

Learn more about SynthCloudConnect →

Capabilities

  • Cross-site DICOM C-STORE bridging (cloud sender → firewall-isolated receiver)
  • Per-tenant result queue with TTL retention + audit
  • Outbound-initiated mTLS WebSocket from on-prem (no inbound firewall changes)
  • Pseudonymization-preserving — round-trips through customer keypair tree
  • Compatible with existing Router AI-vendor routing rules
  • Self-hosted single-tenant deployment (Windows MSI or Linux systemd tarball) plus a Synthology-hosted multi-tenant variant

SynthConstellation™

Non-Device · §520(o)(1)(D)

One console for the whole fleet.

A single pane of glass for your application fleet. See every application's health, queues, and config-sync posture at a glance — then open any application's own console right from the board, with single sign-on, so you view and run your applications from one location instead of logging into each. SynthConstellation also runs the customer-controlled config-backup hub, which any enrolled XyDromatics product can use: each seals its configuration to the console automatically, on a schedule, so a lost or replaced host reseeds its exact configuration from the hub. It moves no images and has no clinical function, but its fleet queues surface the patient identifiers your products report — so it is PHI-bearing, a HIPAA Business Associate under your BAA. Non-device software.

Learn more about SynthConstellation →

Capabilities

  • Single pane of glass — see and reach every application from one board
  • Application health, queue depth, and config-sync posture at a glance
  • Open any application's console from the board with single sign-on (delegated identity)
  • Automated Config Backup Hub — enrolled products seal their configuration on a schedule
  • Restore or reseed a product's exact configuration from the hub (disaster recovery)
  • Sealed off-site Hub Backup of the console itself; hash-chained audit + RBAC

SynthPulse™

General-purpose business software · Non-medical-device

Monitoring for the products we didn't build.

Black-box liveness monitoring for the third-party and other-vendor systems running alongside your Synthology fleet. SynthGateway watches every Synthology and XyDromatics product from the inside; SynthPulse extends that to a foreign PACS, an HL7 interface, a database, or a DICOM listener — probing from the outside for reachability, TLS certificate expiry, and a real DICOM C-ECHO, and reporting to the same gateway so the whole environment lands in one view. Its own admin console shows what is monitored, what is down right now and a week of history, and lets you add, edit and test targets without a restart. A Windows service or Linux systemd daemon, one site licence, PHI-free by design. General-purpose business software; not a medical device.

Learn more about SynthPulse →

Capabilities

  • Black-box liveness probes — reachability, HTTP status, TLS certificate expiry
  • Raw transport connect on any port (HL7/MLLP, a database, a DICOM listener)
  • A real DICOM C-ECHO — proves the peer accepts an association, not just an open port
  • Admin console: Dashboard, Targets, Results (7-day history), Gateway link — edits apply in seconds
  • Targets from your host and from the gateway (support adds them on a call, no restart); local rows win
  • One site licence, RBAC, LDAP / AD sign-in; PHI-free by design — numeric liveness metrics only

Long-term DICOM storage

Archive

The DICOM archive hosts — one binary per regulatory classification. C-STORE receive, an archive catalog, and DICOMweb endpoints over pluggable storage backends (local / S3 / NAS, PostgreSQL catalog), with a Research-Use-Only sibling for de-identified study sets.

XyDromatics™ Repository

Non-Device · §520(o)(1)(D)

Long-term DICOM archive.

The DICOM archive host. C-STORE SCP, archive catalog, and DICOMweb endpoints. Pluggable archive store backends: local filesystem, S3-compatible object stores, on-prem NAS. PostgreSQL for the catalog.

Learn more about Repository →

Capabilities

  • Pluggable archive store (local / S3 / NAS)
  • PostgreSQL catalog DB
  • DICOMweb (QIDO-RS, WADO-RS) for browser access
  • Lifecycle policies + tiering
  • Per-AE-Title access control
  • Hash-chain-verified write log for regulated retention

XyDromatics™ Migration

Non-Device · §520(o)(1)(D)

Archive-to-archive migration.

Migrate studies from a legacy PACS/VNA into a target archive — any source, any destination, any DICOM-conformant target. Includes per-study verification, retry on transient failures, scheduling, and progress reporting.

Learn more about Migration →

Capabilities

  • Multi-source ingestion (C-STORE SCU/SCP, STOW-RS, file watchers)
  • Per-study verification + checksum
  • Pause/resume + scheduled migration windows
  • Migration progress reporting
  • Tag transformation during migration

XyDromatics™ Research

RUO · §520(o)(1)(D)

RUO research-only archive.

A Research-Use-Only sibling of the archive line. PHI-anonymized by design, decoupled from clinical workflows, suited for de-identified study sets and longitudinal research projects.

Learn more about Research →

Capabilities

  • PHI anonymization at ingest
  • Cohort-level access control
  • Project-scoped data partitioning
  • Export de-identified DICOM Part-10 study bundles with a JSON manifest
  • NOT for clinical decision-making

Focused subsets

Specialized engines

Smaller-footprint products extracted from the Router for specific use cases — structured reporting, migration, whole-slide pathology, encounter workflows. Each is a standalone licensed SKU.

XyDromatics™ Migration Engine

Non-Device · §520(o)(1)(D)

Standalone migration appliance.

A standalone migration appliance distinct from XyDromatics Migration. DICOM-only bulk study migration — Q/R pull from a source PACS, C-STORE push to the target. Suited for short-lived migration projects where deploying the full XyDromatics Migration product is overkill.

Learn more about Migration Engine →

Capabilities

  • DICOM Q/R pull + C-STORE push (no HL7)
  • Scheduled sends with retry
  • No persistent archive (transient routing)
  • Standalone licensable SKU

XyDromatics™ De-Identification Engine

Non-Device · §520(o)(1)(D) · RUO output

Raw PHI in, research-safe data out.

The one-way de-identification appliance. Accepts studies and reports across an untrusted network over mutually-authenticated encrypted channels (DICOM-TLS C-STORE, MLLP-over-TLS, DICOMweb STOW-RS), applies HIPAA Expert-Determination de-identification — keyed pseudonymization, interval-preserving date shift, free-text and burned-in-pixel scrubbing — and forwards de-identified output plus PHI-free coded concepts to XyDromatics Research. Runs Synthology-hosted (cloud) or customer-operated (on-prem). Output is Research-Use-Only.

Learn more about De-Identification Engine →

Capabilities

  • Secure cross-network ingest — DICOM-TLS / MLLP-TLS / DICOMweb STOW-RS (all mTLS, fail-closed)
  • Keyed pseudonymization + interval-preserving date shift (DCM 113107)
  • Content gate — free-text scrub + burned-in pixel OCR redaction + document handling
  • HL7 v2 ORU de-identification with cross-protocol demographic alignment
  • Coded-concept harvest → Clinical Cohort Builder (two-person Expert-Determination gate)
  • Re-identification key lives only on the engine — never crosses the wire

XyDromatics™ Identity Trust

General-purpose business software

One directory for the whole shop.

A standalone, standards-compliant LDAPv3 directory. Create every user account once, and every application in the building authenticates against it instead of keeping its own separate logins. Built for smaller facilities that never stood up a corporate directory: a single self-contained server (SQLite by default, PostgreSQL for a replicated pair), an admin console as the primary way to manage people and groups, and manager-DN binds for scripted provisioning. Because it speaks standard LDAP, any LDAP-aware application can point at it — the Synthology fleet included, by configuration alone.

Learn more about Identity Trust →

Capabilities

  • Standards-compliant LDAPv3 — any LDAP client, not just Synthology
  • inetOrgPerson people + groupOfNames groups with memberOf
  • LDAPS / StartTLS, simple bind, RFC-4515 search, Password-Modify, paged results
  • Admin console as the primary management path; manager-DN binds for scripted provisioning
  • Single self-contained server — SQLite by default, PostgreSQL for a replicated/highly-available pair
  • The Synthology fleet binds to it by configuration — no per-application setup

XyDromatics™ Device Registry

Non-Device · §520(o)(1)(D)

Every connected DICOM device, catalogued.

An always-current inventory of every DICOM device on your imaging network. Deployed as a metadata-only DICOM destination behind any vendor's router, it reads each device's network identity (Calling AE, host / IP / port, negotiated SOP class + transfer syntax) and equipment identity from image headers (manufacturer, model, serial number, software version, station, institution), then discards the object. Optional C-ECHO reachability checks confirm which devices are live. Pixel data and patient identifiers are dropped on receipt — the registry keeps device metadata only, no PHI at rest.

Learn more about Device Registry →

Capabilities

  • Passive, metadata-only DICOM capture behind any vendor's router
  • Network identity — Calling AE, host / IP / port, negotiated SOP class + transfer syntax
  • Equipment identity from image headers — manufacturer, model, serial, software version, station, institution
  • Optional C-ECHO reachability probing of known device peers
  • PHI-minimizing by design — pixel data + patient identifiers discarded on receipt, no PHI at rest
  • Rolls up into SynthInSight for a fleet-wide, PHI-free device inventory

SynthInSight™

General-purpose business software · Non-medical-device

Historical + cross-router fleet analytics.

A standalone analytics surface over the operational history your Synthology products archive. Each product writes a compact, gzipped-NDJSON event archive off its hot database; SynthInSight reads that archive with an embedded columnar (DuckDB) query engine and answers all-time and cross-router questions the live operational dashboards can't — without ever touching the ingest path. Aggregate-only by design: counts, distinct-counts, and daily series — never row-level PHI. Deploys independently of every other product.

Learn more about SynthInSight →

Capabilities

  • All-time + cross-router aggregate analytics (count, distinct-count, daily series)
  • Reads the gzipped-NDJSON archive each product's EventArchiver writes — off the hot operational DB
  • Embedded DuckDB columnar query engine (managed-writer / native-reader split)
  • Aggregate-only by design — never returns row-level PHI
  • Bearer-token-gated HTTP API; deploys independently of any other product
  • Windows MSI or Linux tarball

Underneath everything

Platform tooling

The internal control plane (SynthQMS) and the regulated-document vault (SynthVault) that the regulated products run on. Available to customers as standalone products as well.

SynthQMS™

Internal control plane (non-medical-device)

Quality management + CRM control plane.

The internal control plane for the Synthology product family. Document control, training, audits, CAPAs, complaints, MDR, change control. Plus customer / contact / pipeline / estimate / invoice tracking. 21 CFR Part 11-aligned audit trail. ISO 13485 + SOC 2 structured.

Learn more about SynthQMS →

Capabilities

  • Controlled-document workflow (draft → review → approve → archive)
  • 21 CFR Part 11 audit trail
  • Training, audits, CAPAs, complaints, MDR
  • CRM (accounts, contacts, leads, pipeline)
  • Estimates, invoices, billing, accounting integration
  • Booth PWA for trade-show lead capture

SynthVault™

General-purpose business software · Non-medical-device · optional Part 11 mode

Versioned document vault.

Generic file versioning with checkout/checkin, hash-chain audit, integrity sweeps, webhooks, backup/restore. The regulated-document storage backbone of the Synthology product family. Customers can opt into Part-11-friendly retention via a license feature.

Learn more about SynthVault →

Capabilities

  • Checkout / checkin / version history
  • Hash-chain-verified audit log
  • Integrity sweep (re-verify all blobs)
  • Webhooks on every checkin
  • Project + folder organization
  • Optional Part-11 retention mode (license feature)

Bundled workflows

Solution suites

Curated bundles of the products above, packaged for a single outcome. The members ship and are licensed independently — the suite is a commercial bundle, not a fused binary.

The Migration Suite™

Solution suite · 3 products

Legacy-PACS retirement, end to end.

Three applications packaged as one legacy-PACS retirement workflow: Migration Engine fronts the legacy PACS and queries each study once (offloading the live production archive), XyDromatics Migration de-duplicates + remediates tags + quality-gates every study before it reaches the net-new PACS, and both engines report PHI-free counts to SynthInSight for one unified Migration Analytics view. PHI stays on the on-prem image path; only counts reach SynthInSight. The members ship and are licensed independently — the suite is a commercial bundle, not a fused binary.

Learn more about Migration Suite →

Capabilities

  • Migration Engine — federated Q/R proxy (acceleration tier)
  • XyDromatics Migration — de-dup, tag remediation, quality gates
  • SynthInSight — one PHI-free Migration Analytics view
  • Less query load on the customer’s live production PACS
  • Remediate + deduplicate on the way into the net-new PACS
  • Best for legacy-PACS retirement + parallel-run cutover

Want a deeper look at any product?

Tell us which products are interesting and we’ll walk through them in detail with the right engineer on our side. 30 minutes, your imaging stack, our products.