Sigmix Sovereign Appliance in a data centre
Sigmix Sovereign AI Rack Servers

Powerful AI.
Inside your building.
Nothing leaves.

Generative AI — chat, documents, images and video — inside your own data centre, sealed from the internet. Empower your employees securely, in weeks, not months — turnkey, plug-and-play, built for organisations that can't send data to the cloud.

Zero internet egress Processed in-Kingdom Fully bilingual · AR / EN
The Sigmix Sovereign AI Appliance — a Sigmix-branded 2U rack server glowing green, mounted in a data-centre rack SIGMIX SOVEREIGN AI APPLIANCE
The Sigmix Sovereign AI Guard — a Sigmix-engineered PCIe validation and scrubbing card
Watch the explainer

Sovereign AI, inside your building — the whole story

Under a minute: how a sealed Sigmix appliance puts powerful AI on your own network, why nothing ever leaves the building, and where the Sigmix Guard™ card fits in.

Enterprise-grade foundations

The world's most trusted hardware, sealed as sovereign AI.

Every Sigmix appliance is built on NVIDIA-qualified Dell PowerEdge servers and a hardened Red Hat Enterprise Linux foundation — validated, hardened and sealed before it ships.

NVIDIA-qualified GPU + server pairing Hardware root of trust · Secure Boot · TPM 2.0 RHEL · CIS / STIG hardened · SELinux enforcing
Turnkey & plug-and-play

Empower your employees securely — in weeks, not months.

We build, harden and seal the appliance in our facility, then ship it ready to rack. No lengthy cloud migration, no integration project — plug it into your network, connect your directory, and your teams are using sovereign AI the same week.

Sigmix appliance racked among enterprise servers
The problem → the solution

Your data can't go to the cloud. Your teams still need AI.

Banks, ministries and regulated enterprises operate under strict data-sovereignty expectations — sending contracts or customer data to a cloud AI service is often impossible. So teams go without, or take risks they shouldn't.

Sigmix removes the trade-off: a single sealed server we install in your rack, running a full AI suite on open models — entirely offline, no telemetry, no way for your data to leave.

How it works

From our facility to your rack — sealed the whole way

STEP 01

We build & seal it

Hardened OS, encrypted disks, your models loaded and verified — shipped ready to run.

STEP 02

You rack it

It connects only to your internal network, authenticates via your directory, and reaches the internet at no point.

STEP 03

Your teams use AI — safely

Chat, search your documents, generate media and reports — all on your hardware, all logged for auditors.

See the platform

One console to run it. One app your teams love.

A control plane your IT & security teams trust — and a fast, private, fully bilingual experience your employees actually use.

Sigmix Sovereign admin console — Performance & Health — running on a Dell PowerEdge appliance
NO EGRESS · AIR-GAPPED — every request served on-box
Admin console

Built for IT & security

  • Live performance & health — active users, throughput, p95 latency, success rate and queue, every request served on-box.
  • Infrastructure at a glance — GPU utilisation, node vitals and internet egress: 0 B, always in view.
  • Employees via Active Directory · AI Models with signed, SHA-256-verified weights · License (no phone-home).
  • A persistent NO EGRESS · AIR-GAPPED badge and a tamper-evident Audit Log on every screen.
Employee app · Arabic-first

Fast, private, and natively bilingual

AI Chat grounded in your files, Documents & Knowledge (RAG), Image, Video and Document creators — the entire experience works natively in Arabic and English with full right-to-left support.

Employee AI Chat, grounded in the company's own files (English)
AI Chat — grounded in your company files
The employee app in Arabic — full right-to-left
Native Arabic · full right-to-left
What it does

A full generative-AI suite — running on your metal

AI Chat

A private assistant your teams can use with sensitive information.

Documents & Knowledge (RAG)

Ask across your own documents, with permissions that respect who sees what.

Image & Social Creator

On-brand images and ready-to-post content, in Arabic and English.

Video & Advert Creator

Short videos and adverts, generated entirely on your own hardware.

Document Creator

Structured, polished documents and reports from a simple prompt.

Fully bilingual

The whole experience, native in Arabic & English, full RTL.

Our own hardware

Sigmix Guard™ — our own hardware, running Sigmix-authored firmware.

Beyond the validated server, an independent layer scrubs sensitive data and anchors a tamper-evident audit trail on every Sigmix appliance today — and our own proprietary PCIe card, running Sigmix-authored firmware, is rolling out to bring that layer into dedicated hardware, separate from the host operating system. Purpose-built, brandable, and sovereign by design.

The Sigmix Guard card — a Sigmix-engineered PCIe validation and scrubbing board running Sigmix-authored firmware
SIGMIX GUARD™ · Sigmix-authored firmware · non-Chinese sourced
What it does

Two jobs — in dedicated hardware, or in software

  • Independent PII & sensitive-data scrubbing — Saudi National ID / Iqama, IBAN, payment-card and credential patterns are detected and redacted before documents enter your knowledge base or a response leaves the box. Designed to support your PDPL, NCA & SAMA obligations.
  • Tamper-evident audit anchoring — every request is hashed into a chained audit anchor. The appliance's FIPS-certified TPM 2.0 signs the exported anchor, which replicates to your SIEM / WORM store — an independent integrity record.
  • Never a single point of failure — if the card is ever absent or faulted, the identical protection runs in software on the same box. Inference is never blocked; the safeguard is never lost.
Sovereign, by design

Proprietary hardware you can point to

A Sigmix-branded PCIe FPGA card — custom bracket, silkscreen and PCIe vendor ID, so it identifies as Sigmix inside your own rack. Sourced from a non-Chinese vendor for sovereignty consistency; the firmware bitstream is AES-256 + eFUSE protected to raise the bar against cloning. It is a Sigmix-engineered hardware module running Sigmix-authored firmware — an independent enforcement layer, not the certified root of trust (that remains the appliance's FIPS-certified TPM).

A Sigmix Guard card being installed into a PCIe slot in a Sigmix appliance
A full-height PCIe card — designed to install in any Sigmix appliance
Sigmix Guard as an independent enforcement and integrity layer inside the sovereign box
An independent enforcement & integrity layer, on-box

Availability. The scrubbing & audit-anchor layer ships with every appliance today on our software path; the hardware-accelerated Sigmix Guard card is a parallel track that adds acceleration and the Sigmix brand as it lands — it never gates a deployment.

For cyber & security teams

Sealed by design. Zero Trust-aligned. Nothing leaves.

A hardened, air-gapped AI appliance with a hardware root of trust, FIPS-validated cryptography, enforced least-privilege and a continuous no-egress guarantee — engineered to pass your security review.

Zero internet egress — default-deny; a continuous canary alerts only if the internet ever becomes reachable.
Hardware root of trust — Silicon RoT → Secure Boot → measured boot → TPM-sealed disk.
FIPS-validated cryptography — NIST CMVP-listed modules, FIPS mode enforced.
Encrypted everywhere — LUKS at rest, TLS 1.3 & mTLS in transit.
Least-privilege — RBAC + row-level isolation, RAG ACLs enforced twice, admin MFA.
Signed & verified supply chain — signed OS/updates, SHA-256 model weights, SBOM + CVE/VEX.
No vendor backdoor — no remote access, no vendor-held key, no phone-home.
Tamper-evident & SIEM-integrated — hash-chained audit, WORM anchor, syslog/CEF or OCSF export.

Straight answers, up front

FIPS validation covers the cryptographic modules, not the entire appliance — we say so because your assessor will check. And this is a single-node appliance with component redundancy, not an HA cluster; for continuous availability, run two independent units behind your load balancer.

For compliance, audit & GRC

Built for the Kingdom's regulators. Evidence-ready on day one.

Engineered to help you satisfy the SAMA Cybersecurity Framework, NCA ECC-2:2024, PDPL and NDMO data-localization — with audit evidence on-screen and exportable, not promised in a slide.

Designed to help you meet:SAMA CSFNCA ECC-2:2024PDPLNDMO data-localization
Aligned with the principles of:ISO/IEC 27001ISO/IEC 42001 (AI)NIST CSFVision 2030 objectives
Data never leaves the Kingdom — 100% on-prem, in-country. No cross-border transfer, no cloud sub-processors.
Full audit trail — who, when, which model, which module — tamper-evident and hash-chained.
ROPA-ready — exportable Records of Processing Activities support for PDPL.
DPO-controlled retention — configurable retention, redaction, legal-hold, no-content-retention mode.
SIEM-ready — logs export to your existing SIEM (syslog/CEF or JSON/OCSF).
Right-to-erasure — cryptographic Secure Erase; you hold the sole encryption key.

Honest by design — which is why it's safe to put in front of your assessor

We don't claim to be "SAMA-approved," "NCA-certified" or a "FIPS-certified appliance" — these frameworks assess your organisation, not our box, and FIPS validation covers the cryptographic modules, not the whole appliance. The ISO/NIST references above are statements of alignment with those standards' principles, not certifications we hold. We give you an appliance designed to help you meet the controls, with the evidence your assessors need — you hold the compliance; we give you the controls and the proof.

Your per-deployment evidence pack:

SAMA CSF mappingNCA ECC-2 mappingPDPL / ROPACIS / STIG scanFIPS certificate refSBOMCVE / VEXSigned provenanceSecure Boot / TPM statusKey-custody statementZero-egress testSIEM export sampleAccess-review sampleRestore-test evidenceModel-license register
How we select the hardware

We don't just ship a server. We validate it.

Every appliance runs on NVIDIA-qualified Dell PowerEdge hardware, put through a defined validation gauntlet — because "it powered on in a lab" isn't "it runs reliably, sealed, in your data centre for years."

What we require of every box

  • NVIDIA-qualified GPU + server pairing (validated combinations only)
  • Full hardware security stack: Silicon RoT, Secure Boot, TPM 2.0, System Lockdown, Chassis Intrusion
  • iDRAC out-of-band management · redundant power + cooling sized for sustained AI load
  • Power-loss-protected NVMe · ECC memory · RAID-1 boot · redundant PSUs
  • RHEL validated on the exact platform · in-Kingdom supply & support

Our validation gauntlet

  • Verify 600W GPU power cabling & measure sustained draw under load
  • No thermal throttling under sustained multi-GPU load — at Kingdom ambient
  • 100× unattended reboot · power-cut mid-inference / mid-update / mid-boot
  • GPU fault-recovery & broken-update rollback · 72-hour soak test
  • FIPS + CIS/STIG scan · zero-egress verification · real-hardware sizing benchmark
Why it's different

Cloud AI vs. the Sigmix Sovereign Appliance

Cloud AISigmix Sovereign Appliance
Where data goesTo the provider's cloudNever leaves your rack
Internet dependencyRequiredNone (sealed)
Vendor access to dataYesNone
Audit / SIEMProvider-controlledYour logs, your SIEM
IdentityProvider accountsYour Active Directory
Regulatory postureA hurdleDesigned to help you comply
Choose your size

Four tiers, sized to your organisation

Indicative sizing — final sizing validated to your usage. Grow between tiers by adding accelerators.

TIER S
2U
1 AI accelerator
  • ~200–250 users
  • A department or team
  • All 7 modules · Bilingual
TIER M
2U
2–3 accelerators
  • ~500–750 users
  • A division / mid-size org
  • All 7 modules · Bilingual
POPULAR
TIER L
4U
4–6 accelerators
  • ~1,500–2,500 users
  • Enterprise-wide
  • All 7 modules · Bilingual
TIER XL
4U
8 accelerators
  • ~2,500–3,500+ users
  • High concurrency
  • All 7 modules · Bilingual

Indicative at ~10% peak concurrency; final sizing validated to your usage. The appliance is a single-node product; for continuous availability run two independent boxes behind your load balancer. Fixed annual license by size and modules, supported through our local Kingdom partner.

Deployment

On-premises, or in your colocation facility

On-premises server room

On-premises

Racked in your own data centre, behind your firewall, on your internal network only.

Colocation cage

Colocated

Your appliance in a sovereign colocation facility — your gear, your keys, your control.

Questions

Answers for your architecture, cyber & procurement teams

Does it connect to the internet?+
No. In its default mode it makes no outbound internet connections at all. Your firewall is the outer boundary; the appliance is sealed as a second layer, with a continuous canary that alerts only if the internet ever becomes reachable.
How do employees log in?+
Through your existing Active Directory (LDAPS), using normal corporate credentials — fully offline. Local accounts and offline signed user-import are also supported.
What about our regulators?+
The appliance is designed to help you meet your obligations under SAMA CSF, NCA ECC-2:2024 and PDPL, with the evidence your security team needs on-screen and exportable. Regulators assess your organisation, not vendor products — we give you the evidence, you hold the compliance.
Is our data ever visible to Sigmix?+
No. There is no vendor remote access and no vendor-held key that can decrypt your data. Diagnostics are exported only by your own administrator, PII-redacted.
Are you "FIPS-certified"?+
We use FIPS 140-3 validated cryptographic modules (NIST CMVP-listed, verifiable by certificate number) with FIPS mode enforced. The validation covers the cryptographic modules, not the entire appliance — we state this precisely rather than claiming a "FIPS-certified appliance."
What happens when the license ends?+
The appliance runs for the licensed term. At renewal we issue a new key that reactivates it — entirely offline, verified locally (Ed25519), no internet required.
Book a technical briefing

Bring us your architecture, cyber & procurement teams

We'll walk them through the full design and compliance mapping — and show exactly how your data never leaves the building.

Your data. Your rack. Your AI.