Sigmix Guard™ our own firmware

Our own hardware, running Sigmix-authored firmware.

An independent layer that scrubs sensitive data and anchors a tamper-evident audit trail on every Sigmix appliance today — now moving into our own proprietary PCIe card, separate from the host OS. Purpose-built, brandable, and sovereign by design.

// Sigmix-authored firmware · vetted supply chain · ships on every appliance today

The Sigmix Guard PCIe card ◆ Sigmix Guard™ · PCIe
Built to answer the auditor
PDPL NCA ECC-2:2024 SAMA CSF TPM 2.0 signed anchors Vetted supply chain Software failover
What it does

Two jobs. Both of them boring, both of them critical.

Guard is not a model, an accelerator or a firewall. It does two specific things on every request that crosses the appliance — and it does them independently of the software that could otherwise be asked to look the other way.

Job 01

Independent PII & data scrubbing

Saudi National ID / Iqama, IBAN, payment-card and credential patterns are detected and redacted before documents enter your knowledge base — or before a response leaves the box. It runs on the request path, not as an after-the-fact report.

PDPLNCASAMArequest path
Job 02

Tamper-evident audit anchoring

Every request is hashed into a chained audit anchor. The appliance's FIPS-validated TPM 2.0 signs the exported anchor, which replicates to your SIEM or WORM store — an independent integrity record that does not depend on the appliance staying honest.

TPM 2.0SIEM / WORMchained hash
On the request path

Where Guard sits.

Everything below happens inside your building. Guard is in the middle of it — not bolted on at the edge, and not reading a log afterwards.

🇸🇦 Inside your building — nothing leaves

Request

A prompt or a document from your staff.

Guard scrubs

ID, Iqama, IBAN, card and credential patterns redacted.

Local model

Inference runs on your own hardware.

Guard anchors

Hashed, chained, TPM-signed, replicated to your SIEM.

Response

Returned to the user. Egress: 0 bytes.

// scrub happens before the model sees it · anchor happens after the model answers · neither step is optional

Availability

Never a single point of failure.

A security control that can take your AI offline is a control your team will eventually be asked to disable. Guard is built so that never becomes the trade-off.

Hardware path

The Guard card

Scrubbing and anchoring run in dedicated silicon, separate from the host OS — so the protection does not share fate with the software it is protecting, and adds acceleration as it lands.

Software failover

Identical protection, same box

If the card is ever absent or faulted, the identical protection runs in software on the same appliance. Inference is never blocked; the safeguard is never lost.

The card

Purpose-built, brandable, sovereign by design.

  • Form factorPCIe card, installs in any Sigmix appliance
  • FirmwareSigmix-authored — not a rebadged third-party image
  • IsolationRuns separate from the host OS, on its own execution path
  • Key protectionAES-256 with eFUSE-backed key storage
  • Supply chainVetted, sovereignty-conscious sourcing
  • BrandingSilkscreened Sigmix Guard™ — our mark on our silicon
  • Failure modeAbsent or faulted → identical protection in software, same box
The Sigmix Guard card installed in a Sigmix appliance Installs in any Sigmix appliance
Be precise about this

What Guard is — and what it isn't.

Security claims get repeated in procurement documents long after the person who wrote them has left. So here is the precise version, in the words we are willing to have quoted back to us.

Guard is an independent enforcement layer — not the certified root of trust.

The root of trust remains the appliance's FIPS-validated TPM 2.0. Guard does not replace it, extend its certification, or inherit it. Guard enforces scrubbing and produces the audit chain; the TPM is what signs the exported anchor and makes it independently verifiable.

Related, and just as important: the appliance uses FIPS-validated crypto modules. That is not the same claim as a "FIPS-certified appliance", and we do not make the second one.

✓ What it is

An independent enforcement layer on the request path · a scrubber that runs before the model sees your data · a chained, TPM-signed audit anchor you can replicate off-box · our own firmware on our own card.

✕ What it is not

Not the certified root of trust · not a FIPS certification for the appliance · not an accelerator for inference · not a gate on your deployment · not a replacement for your own controls and review.

Availability, stated plainly. The scrubbing and audit-anchor layer ships with every appliance today, on the software path. The hardware-accelerated Sigmix Guard card is a parallel track that adds acceleration and the Sigmix brand as it lands — it never gates a deployment. If you buy an appliance today, you get the protection today.
Questions

For your security and procurement teams

Do we have to wait for the card to get the protection?
No. The scrubbing and audit-anchoring layer ships with every Sigmix appliance today, running on the software path. The card is a parallel track that adds dedicated silicon and acceleration — it never gates a deployment, and it is not a prerequisite for the security property.
Is the appliance FIPS certified?
No, and we are careful with this wording. The appliance uses FIPS-validated crypto modules, and the TPM 2.0 that signs audit anchors is FIPS-validated. "FIPS-validated crypto modules" and "FIPS-certified appliance" are different claims; only the first one is ours to make.
Is Guard the root of trust?
No. Guard is an independent enforcement layer. The certified root of trust remains the appliance's FIPS-validated TPM 2.0 — that is what signs the exported audit anchor and makes it verifiable outside the box. Guard enforces; the TPM attests.
What happens if the card fails?
The identical protection runs in software on the same appliance. Inference is never blocked and the safeguard is never lost. This is deliberate: a control that can take your AI offline is a control someone will eventually be asked to switch off.
What exactly does it scrub?
Saudi National ID and Iqama numbers, IBANs, payment-card numbers and credential patterns — detected and redacted before documents enter a knowledge base, and before a response leaves the appliance. The pattern set is configurable for your environment during deployment.
Where does the audit anchor go?
To your SIEM or WORM store, not ours. Each request is hashed into a chained anchor, the TPM signs the export, and it replicates to infrastructure you control — so the integrity record survives independently of the appliance and of us.
What about the supply chain and firmware provenance?
The firmware is Sigmix-authored rather than a rebadged third-party image, and the hardware supply chain is vetted for sovereignty-critical buyers. The provenance of the silicon is part of the security question, not separate from it — we will walk your team through the specifics under NDA in the briefing.
Talk to us

Bring your security team.

The useful conversation about Guard is a technical one — the pattern set, where the anchors land, how it maps to your NCA and SAMA obligations, and what we are not claiming. Book the briefing and bring the people who will have to defend the choice.

Guard ships inside the Sovereign AI Servers and Sigmix Zero. It is not sold as a standalone card.