Our PCIe card, running Sigmix-authored firmware — scrubbing & audit, in dedicated silicon.
Explore Sigmix Guard
Every request served on-box, sealed from the internet.
See your postureEverything your security, risk and procurement teams need to assess Sigmix — the controls we run, the frameworks we map to, who processes what and where, and a plain statement of what we do not claim.
Vendor security pages tend to imply certifications nobody actually holds. Ours is written to survive being quoted back at us in a procurement review, so it is deliberately narrower than it could be.
There is no such thing as a "SAMA-certified" or "NCA-certified" AI platform. Those frameworks certify you. What a vendor can honestly do is build controls that map cleanly onto your obligations, and hand your team the evidence to demonstrate them. That is what this page is for.
So we say "designed to support your obligations under PDPL, SAMA CSF and NCA ECC-2:2024", and we provide the control mapping. We do not say we are certified against them, because we would be describing your accreditation, not ours.
FIPS-validated crypto modules. Designed to support PDPL, SAMA CSF and NCA ECC-2. Zero egress by architecture on sealed postures.
FIPS-certified appliance. SAMA-certified. NCA-certified. Guard is not the certified root of trust — the FIPS-validated TPM is.
Scene understanding and forecasting are probabilistic. Anything consequential is flagged for human review, never auto-decided.
The detailed control-by-control mapping is released under NDA as part of the evidence pack. This is the summary.
| Framework | Our position | What we provide |
|---|---|---|
| NCA ECC-2:2024 | Designed to support | Control mapping covering asset protection, access control, cryptography, logging and network segregation. Sealed deployment removes whole classes of control from scope. |
| SAMA CSF | Designed to support | Mapping for data protection, third-party risk, logging and monitoring. Zero-egress posture is the usual answer to the data-transfer questions. |
| PDPL | Aligned by design | Residency, retention limits, right-to-erasure via crypto-shredding, PII scrubbing on the request path, and a tamper-evident access log. |
| ZATCA | Compliant invoicing | Bilingual tax invoices issued natively by the platform, not produced by a bolt-on. |
| Vision 2030 | Aligned | Built in the Kingdom by a MISA-licensed Saudi entity, with in-Kingdom compute and Arabic-first output. |
| FIPS 140 | Validated modules only | The appliance uses FIPS-validated crypto modules, including the TPM 2.0 that signs audit anchors. The appliance itself is not FIPS-certified and we do not claim it is. |
| ISO 27001 | Not held today | Not currently certified. We would rather list this honestly than let a logo imply otherwise. Ask us for our current roadmap position in the briefing. |
On sealed on-prem and on-device postures the honest answer is "nobody but you" — there is no outbound path for a subprocessor to sit on. The list below applies to the cloud postures.
Released under NDA to organisations in an active evaluation. Ask for it in the briefing and we will send the current version rather than a marketing summary.
Control-by-control mapping against NCA ECC-2:2024, SAMA CSF and PDPL.
Where data sits, what crosses which boundary, and what does not cross at all.
The signed, current list with purpose and jurisdiction for each party.
Anchor format, signing chain, and how it lands in your SIEM or WORM store.
What models run in each posture and under which licences.
How we respond, who we notify, and in what timeframe.
If you believe you have found a vulnerability in a Sigmix product or service, report it directly and we will acknowledge it. We ask for reasonable time to remediate before public disclosure, and we will not pursue researchers who act in good faith, avoid privacy violations and do not degrade service.
Sovereignty claims mean little from a company incorporated somewhere else. These are the registrations your procurement team will ask for.
We would rather answer your standard assessment than have you read ours. Send the questionnaire ahead of the briefing and we will come back with the evidence pack and the control mapping filled in.