Sovereign AI Servers · on-prem appliance

Powerful AI inside your building. Nothing leaves.

Generative AI — chat, documents, image and video — inside your own data centre, sealed from the internet. Built, hardened and shipped ready to rack. Live in weeks, not months.

// no egress · sealed · SHA-256 verified weights

A sealed Sigmix appliance aisle in an in-Kingdom data centre Racked & sealed · egress 0 B
Enterprise foundations, sovereign posture
NVIDIA-qualified Dell Technologies Authorized Partner Hardened RHEL CIS / STIG SELinux enforcing Secure Boot · TPM 2.0
What it is

A sealed generative-AI stack, on your own metal.

Not a private cloud tenancy, not a VPC with a promise attached. A physical appliance in your rack, running your models, with no path to the internet.

Enterprise-grade foundations

NVIDIA-qualified Dell PowerEdge on a hardened Red Hat Enterprise Linux base — CIS/STIG hardened, SELinux enforcing, Secure Boot and TPM 2.0.

Dell Authorized PartnerRed HatNVIDIA-Qualified

Zero internet egress

Default-deny networking with continuous canary alerts if the internet ever becomes reachable. GPU health, utilisation and egress: 0 B are visible in the admin console.

default-denycanary alertsegress 0 B

Turnkey — weeks, not months

Ships pre-sealed and hardware-verified. Active Directory integration, tamper-evident audit log, and a native Arabic + English employee app on day one.

pre-sealedAD integrationAR + EN
Dell Technologies Authorized Partner

A Dell Technologies Authorized Partner.

The appliance is built on NVIDIA-qualified Dell PowerEdge — and we are authorised by Dell to do it. That is not a badge for the website: it is why your procurement team gets genuine Dell hardware with a real warranty, a spares path and Dell's own service network in the Kingdom standing behind the box in your rack.

Genuine hardwareAuthorised supply, not grey-market boxes. Warranty & sparesDell's support path, not ours alone. Easier procurementAn authorised partner clears vendor review faster.
Admin console

Prove the seal, from one screen.

The claim that nothing leaves is only worth what you can verify. The console shows live performance and health next to the number that matters — outbound bytes.

The Sigmix admin console — live performance, GPU health and egress counter Admin console · live · egress 0 B
Live performance & healthGPU utilisation, thermals and job throughput in real time.
Egress counterThe outbound byte count, on screen, continuously.
SHA-256 verified weightsModel weights checksum-verified — you can prove what is running.
Tamper-evident audit logChained and exportable to your SIEM or WORM store.
◆ Sigmix Guard™ · inside

Our own enforcement layer, in every appliance.

Saudi National ID, Iqama, IBAN, payment-card and credential patterns are scrubbed before documents reach your knowledge base, and every request is hashed into a TPM-signed audit anchor on the way out. It ships on the software path with every appliance today — the hardware card is a parallel track that never gates a deployment.

Explore Sigmix Guard
The Sigmix Guard PCIe card
Sizing

One node, a cluster, or an in-Kingdom cage.

The same sealed software in every footprint. What changes is how much compute sits behind it — and whether the rack is in your building or a colocation facility inside Saudi Arabia.

A single Sigmix appliance on-site

Single node

One appliance, one site. The usual starting point — a department, a branch, a single sensitive workload.

A Sigmix cluster

Cluster

Multiple nodes for capacity and continuity — more concurrent users, larger models, no single box to lose.

Sigmix in an in-Kingdom colocation cage

In-Kingdom colocation

Your sealed rack in a Saudi facility — dedicated cage, not shared cloud, when you would rather not run the room.

Final sizing is engineered against your workload — concurrent users, model tier and retention — not picked from a table. The briefing is where that gets worked out.
Turnkey

What arrives on the loading dock.

Pre-sealed and hardware-verified before it leaves us, so the deployment is a rack-and-configure job rather than a build project.

Weeks, not months

Built, hardened, shipped ready to rack.

Every unit is assembled, hardened and verified before shipping. Your team racks it, joins it to Active Directory and points staff at the app — the AI stack, the hardening and the seal are already done.

A Sigmix appliance racked and sealed on site Hardware-verified before it ships
Active Directory integrationYour existing identities and groups, day one.
Native Arabic + English appFull RTL, not a translation layer.
Sigmix Guard layerScrubbing and audit anchoring, enabled by default.
Pre-sealed & verifiedHardware-verified before dispatch; sealed on arrival.
Questions

For infrastructure, security and procurement

Does the appliance need internet access at all?
No. It runs default-deny and is designed to operate with no outbound path. Continuous canary checks alert you if the internet ever becomes reachable — the alert exists because a silent change in your network is the realistic failure mode, not ours.
How do model updates work without egress?
Updates are delivered as verified media and applied deliberately by your team. Weights are SHA-256 checksum-verified, so you can prove exactly what is running on the box before and after. Nothing self-updates over a network that is not supposed to exist.
Whose hardware is it?
NVIDIA-qualified Dell PowerEdge on hardened Red Hat Enterprise Linux — deliberately boring, supportable enterprise hardware your team can already service, rather than something exotic only we can maintain.
How long does deployment actually take?
Weeks rather than months, because the appliance is built, hardened and verified before it ships. The variable is your side — network, Active Directory, and the security review — not assembling the AI stack.
Can we run it in a colocation facility instead?
Yes — a dedicated sealed cage in an in-Kingdom facility. Same software, same posture; the difference is who racks it and runs the room. Data residency stays inside Saudi Arabia either way.
Is it FIPS certified?
The appliance uses FIPS-validated crypto modules, including the TPM 2.0 that signs audit anchors. That is not the same claim as a "FIPS-certified appliance", and we do not make the second one.
Next step

Bring your infrastructure team.

The useful conversation is a technical one — power and rack space, network posture, Active Directory, model tiers, retention and how the audit trail reaches your SIEM. Book the briefing and bring the people who will run it.

Need the same sovereignty on a desk rather than in a rack? See Sigmix Zero — the on-device edition of the same suite.