Trust Center

The evidence, not the adjectives.

Everything your security, risk and procurement teams need to assess Sigmix — the controls we run, the frameworks we map to, who processes what and where, and a plain statement of what we do not claim.

Where we stand

What we claim, and what we don't.

Vendor security pages tend to imply certifications nobody actually holds. Ours is written to survive being quoted back at us in a procurement review, so it is deliberately narrower than it could be.

Regulators assess your organisation, not vendor products.

There is no such thing as a "SAMA-certified" or "NCA-certified" AI platform. Those frameworks certify you. What a vendor can honestly do is build controls that map cleanly onto your obligations, and hand your team the evidence to demonstrate them. That is what this page is for.

So we say "designed to support your obligations under PDPL, SAMA CSF and NCA ECC-2:2024", and we provide the control mapping. We do not say we are certified against them, because we would be describing your accreditation, not ours.

We do say

FIPS-validated crypto modules. Designed to support PDPL, SAMA CSF and NCA ECC-2. Zero egress by architecture on sealed postures.

We don't say

FIPS-certified appliance. SAMA-certified. NCA-certified. Guard is not the certified root of trust — the FIPS-validated TPM is.

Where we're honest about limits

Scene understanding and forecasting are probabilistic. Anything consequential is flagged for human review, never auto-decided.

Framework mapping

How our controls line up with your obligations.

The detailed control-by-control mapping is released under NDA as part of the evidence pack. This is the summary.

FrameworkOur positionWhat we provide
NCA ECC-2:2024 Designed to support Control mapping covering asset protection, access control, cryptography, logging and network segregation. Sealed deployment removes whole classes of control from scope.
SAMA CSF Designed to support Mapping for data protection, third-party risk, logging and monitoring. Zero-egress posture is the usual answer to the data-transfer questions.
PDPL Aligned by design Residency, retention limits, right-to-erasure via crypto-shredding, PII scrubbing on the request path, and a tamper-evident access log.
ZATCA Compliant invoicing Bilingual tax invoices issued natively by the platform, not produced by a bolt-on.
Vision 2030 Aligned Built in the Kingdom by a MISA-licensed Saudi entity, with in-Kingdom compute and Arabic-first output.
FIPS 140 Validated modules only The appliance uses FIPS-validated crypto modules, including the TPM 2.0 that signs audit anchors. The appliance itself is not FIPS-certified and we do not claim it is.
ISO 27001 Not held today Not currently certified. We would rather list this honestly than let a logo imply otherwise. Ask us for our current roadmap position in the briefing.
Controls

What actually runs.

Data protection

  • AES-256 at rest with per-tenant keys
  • TLS in transit, terminating in-Kingdom for sovereign tenants
  • Credentials stored by reference, never in the clear
  • Right-to-erasure via crypto-shredding

Isolation

  • Tenant isolation enforced in the database itself
  • Enforced again at the application layer
  • Dedicated in-Kingdom capacity available for regulated clients
  • Sealed postures are physically separate by definition

Integrity & audit

  • Chained, tamper-evident audit anchors
  • TPM 2.0 signs the export; replicates to your SIEM / WORM
  • SHA-256 verified model weights
  • Every credit and billing movement ledgered and reconcilable

Network posture

  • Default-deny networking on sealed deployments
  • Continuous canary alerts if the internet becomes reachable
  • No remote-access path by design on sealed postures
  • Optional maintenance tunnel is customer-controlled and revocable

Build & supply chain

  • Automated vulnerability and code-security scanning gates the build
  • DigiCert code-signed installers
  • Dell Technologies Authorized Partner — genuine, warrantied hardware supply
  • Sigmix-authored firmware on a vetted supply chain in Sigmix Guard
  • No AGPL or non-commercial-licensed models in production

Identity & access

  • Active Directory / SSO integration, included
  • Argon2id password hashing
  • Capability gates set centrally, with an audit trail of changes
  • Face recognition ships disabled behind an explicit admin gate
Residency & subprocessors

Who touches your data, and where.

On sealed on-prem and on-device postures the honest answer is "nobody but you" — there is no outbound path for a subprocessor to sit on. The list below applies to the cloud postures.

PartyPurposeLocation
Oracle CloudKSA Cloud compute and storage — the primary in-Kingdom postureSaudi Arabia · Riyadh, Jeddah
Google CloudAdditional in-Kingdom capacitySaudi Arabia · Dammam
Global Cloud tierFrontier / foundational models — opt-in, clearly labelled, never a defaultInternational
Anything marked International is opt-in and named. Customer media is never replicated across borders on the in-Kingdom postures, and the sealed postures have no subprocessors at all. The current signed subprocessor list forms part of the evidence pack.
For your review

The evidence pack.

Released under NDA to organisations in an active evaluation. Ask for it in the briefing and we will send the current version rather than a marketing summary.

Control mapping

Control-by-control mapping against NCA ECC-2:2024, SAMA CSF and PDPL.

Architecture & data-flow

Where data sits, what crosses which boundary, and what does not cross at all.

Subprocessor register

The signed, current list with purpose and jurisdiction for each party.

Audit-log specification

Anchor format, signing chain, and how it lands in your SIEM or WORM store.

Model & licence inventory

What models run in each posture and under which licences.

Incident & continuity plan

How we respond, who we notify, and in what timeframe.

Responsible disclosure

Found something? Tell us.

We would rather hear it from you.

If you believe you have found a vulnerability in a Sigmix product or service, report it directly and we will acknowledge it. We ask for reasonable time to remediate before public disclosure, and we will not pursue researchers who act in good faith, avoid privacy violations and do not degrade service.

Security contactlegal@sigmix.sa
Acknowledgement target2 business days
Privacy & data requestsdpo@sigmix.sa
Who you are contracting with

A Saudi entity, on the record.

Sovereignty claims mean little from a company incorporated somewhere else. These are the registrations your procurement team will ask for.

Commercial registrationCR 7054521799
VAT314836510700003
MISA licence24926260339
RegisteredRiyadh, KSA
Next step

Send us your security questionnaire.

We would rather answer your standard assessment than have you read ours. Send the questionnaire ahead of the briefing and we will come back with the evidence pack and the control mapping filled in.

Legal terms — privacy policy, terms of service, acceptable use and sales terms — are linked in the footer of every page.