A doctor working through documentation on a sealed device
Healthcare

Patient data that never leaves the building.

Clinical notes are the most sensitive free text a hospital holds — and exactly the material staff most want help with. Sigmix resolves that tension architecturally: the model runs on your hardware, so the notes never go anywhere to be helped with.

Built for Saudi healthcare
PDPL-aligned NCA ECC-2:2024 On-device or sealed on-prem Human in the loop Arabic + English
The problem, stated plainly

Staff are already using AI. The question is where.

Ask honestly and most hospitals find clinicians and administrators already pasting work into consumer AI tools on personal accounts — because the job is hard and the tool helps. That is the real data-protection exposure, and a policy banning it has not closed it anywhere.

A ban moves the risk. It doesn't remove it.

The instinct is to prohibit AI on clinical material. In practice that pushes usage onto personal devices and accounts you cannot see, audit or govern — and the sensitive text still leaves the building, just without a record of it.

Giving staff a sanctioned tool that runs inside the hospital removes the reason to go elsewhere. The work gets done, the data stays put, and for the first time there is an audit trail of what was asked and by whom.

✕ Policy-only approach Unsanctioned tools, no visibility

Notes pasted into consumer AI on personal accounts. No audit trail, no residency control, and no way to evidence any of it to a regulator.

✓ Sanctioned, sealed deployment Same help, inside your walls

Models run on hospital hardware. PII scrubbed on the request path, every request audit-anchored, nothing transmitted anywhere.

Where it earns its place

Documentation, not diagnosis.

Sigmix is a documentation and administration tool. It drafts, summarises, translates and answers questions across material you already hold. It does not diagnose, triage or make clinical decisions, and we would rather be clear about that than sell into a claim we cannot stand behind.

Clinical judgement stays entirely with the clinician. Anything the system produces is a draft for a person to review, correct and own.

A doctor drafting documentation on a sealed device On-device · nothing transmitted

Documentation support

Tidying notes, drafting letters and discharge summaries, restructuring dictated text — on the device, reviewed by the clinician.

Protocol & policy lookup

Ask questions across your own clinical guidance and internal policy, in Arabic or English, with the source attached.

Administrative load

Rosters, correspondence, procurement documents and reporting for the non-clinical teams who carry most of the paperwork.

Bilingual by default

Arabic-native output for a workforce that documents in both languages, with full right-to-left throughout.

Identifiers scrubbed first

National ID, Iqama, MRN-style patterns and contact details redacted on the request path — before the model, not after the fact.

Audit trail for the regulator

Every request hashed into a tamper-evident anchor and exportable to your SIEM — the evidence a PDPL review asks for.

How hospitals deploy it

Sealed desks first, then the department.

The common starting point is Sigmix Zero on the desks handling the most sensitive material — medical records, HR, legal, the executive floor. The models run on the machine, so the question of transmission never arises.

Where a whole department needs shared capacity, an on-prem appliance serves the building with the same posture — sealed, zero-egress, nothing leaving the site.

Two clinicians reviewing documentation together Records & administration
A nurse updating records at a station
Nursing staff, updating records on the ward.
Hospital records administration
Records and administration, where the paperwork actually lives.
On regulatory scope: Sigmix is not a medical device and is not certified as one. It is an office and documentation tool used alongside your clinical systems — if a use case starts to look like clinical decision support, that is a different regulatory conversation and we will say so.
For your DPO and compliance lead

What you can evidence.

PDPL asks you to demonstrate control, not to promise it. These are the artefacts the platform produces for that conversation.

0 Begress on sealed postures
Chainedtamper-evident audit anchors
Per-tenantAES-256 keys
Neverused to train a model

Control mapping

Mapping against PDPL and NCA ECC-2:2024, released under NDA in the evidence pack. Trust Center →

Retention & erasure

Retention limits and right-to-erasure via crypto-shredding, configurable to your own records policy.

Identity & access

Active Directory or SSO, with capability gates set centrally and every change recorded.

Questions

For clinical governance, IT and procurement

Is this a medical device?
No, and we do not market it as one. Sigmix is a documentation and administration tool — it drafts, summarises and answers questions across material you hold. It does not diagnose, triage or make clinical decisions. If a proposed use case crosses into clinical decision support, that is a regulated category and a different conversation; we will tell you rather than take the order.
Where do patient notes go?
On Sigmix Zero, nowhere — the model runs on the machine and the note never traverses a network. On a sealed on-prem appliance, it stays inside the building with no outbound path. In neither case is any content used to train a model.
How does it handle identifiers?
Sigmix Guard scrubs Saudi National ID, Iqama, payment-card and credential patterns on the request path — before the model sees them and before anything enters a knowledge base. The pattern set is configurable for your environment during deployment.
Can we prove to a regulator what happened?
Yes. Every request is hashed into a chained, tamper-evident audit anchor which replicates to your SIEM or WORM store. The record lives on infrastructure you control, so it survives independently of the appliance and of us.
Does it integrate with our HIS or EMR?
Not as a drop-in module today. Most hospitals start with it alongside those systems — staff work in Sigmix for drafting and lookup rather than replacing the clinical record. Where deeper integration matters, the API is the route, and that is a scoping conversation in the briefing.
What about Arabic clinical language?
Output is generated by an Arabic-first model rather than translated, and the interface mirrors to full right-to-left. Clinical Arabic is specific, so test it against your own documentation during evaluation — that is the fastest way to judge it.
A doctor writing notes at the end of a shift
Next step

Bring your DPO to the first call.

The useful conversation is about scope and evidence — what staff would actually use it for, which identifiers get scrubbed, and where the audit trail lands. Bring the person who will have to answer for it under PDPL.